Lesson 5 of 28 · javascript
Security Best Practices
Duration: 10 mins
Security Best Practices
| Recommendation | Why it matters |
|---|---|
Enable contextIsolation | Prevents the page from accessing Node globals. |
Disable nodeIntegration | Stops arbitrary scripts from requiring Node modules. |
| Use a preload bridge | Exposes only the API you intend. |
Set a strong Content‑Security‑Policy | Blocks XSS and unwanted remote scripts. |
| Validate all IPC data | An attacker could craft a malicious message. |
Enable sandbox: true for renderers (optional) | Runs the renderer in a Chromium sandbox, further limiting privilege. |
Avoid eval/new Function | Execution of arbitrary code is a common injection vector. |
| Sign your app (macOS & Windows) | Prevents tampering and improves user trust. |
Example CSP header in renderer HTML
<meta http-equiv="Content-Security-Policy" content="default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:;">