[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:frontend\u002Fweb-security":4,"config":235},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":133,"samples":150},"frontend","Frontend","","web-security","Web Security","en",75,2925,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,51,54,57,60,63,66,69,72,75,78,81,84,87,90,93,96,99,102,105,108,111,114,117,120,123,126,129,132],{"key":19,"name":20,"count":11},"accessibility","Accessibility",{"key":22,"name":23,"count":11},"angular-change-detection","Angular Change Detection",{"key":25,"name":26,"count":11},"angular-components-lifecycle","Angular Components Lifecycle",{"key":28,"name":29,"count":11},"angular-dependency-injection","Angular Dependency Injection",{"key":31,"name":32,"count":11},"angular-directives-pipes","Angular Directives Pipes",{"key":34,"name":35,"count":11},"angular-router-forms","Angular Router Forms",{"key":37,"name":38,"count":11},"angular-testing-performance","Angular Testing Performance",{"key":40,"name":41,"count":11},"css-layout","Css Layout",{"key":43,"name":44,"count":11},"dom-browser-apis","Dom Browser Apis",{"key":46,"name":47,"count":11},"javascript-async-concurrency","Javascript Async Concurrency",{"key":49,"name":50,"count":11},"javascript-language","Javascript Language",{"key":52,"name":53,"count":11},"javascript-memory-performance","Javascript Memory Performance",{"key":55,"name":56,"count":11},"javascript-modules-bundling","Javascript Modules Bundling",{"key":58,"name":59,"count":11},"javascript-prototypes-oop","Javascript Prototypes Oop",{"key":61,"name":62,"count":11},"javascript-runtime-apis","Javascript Runtime Apis",{"key":64,"name":65,"count":11},"javascript-testing-tooling","Javascript Testing Tooling",{"key":67,"name":68,"count":11},"performance","Performance",{"key":70,"name":71,"count":11},"react-components-jsx","React Components Jsx",{"key":73,"name":74,"count":11},"react-context-state","React Context State",{"key":76,"name":77,"count":11},"react-effects-lifecycle","React Effects Lifecycle",{"key":79,"name":80,"count":11},"react-forms-suspense","React Forms Suspense",{"key":82,"name":83,"count":11},"react-hooks-state","React Hooks State",{"key":85,"name":86,"count":11},"react-rendering-performance","React Rendering Performance",{"key":88,"name":89,"count":11},"rendering-reactivity","Rendering Reactivity",{"key":91,"name":92,"count":11},"state-management","State Management",{"key":94,"name":95,"count":11},"testing","Testing",{"key":97,"name":98,"count":11},"typescript-advanced-types","Typescript Advanced Types",{"key":100,"name":101,"count":11},"typescript-generics","Typescript Generics",{"key":103,"name":104,"count":11},"typescript-modules-declarations","Typescript Modules Declarations",{"key":106,"name":107,"count":11},"typescript-narrowing-control-flow","Typescript Narrowing Control Flow",{"key":109,"name":110,"count":11},"typescript-tooling-config","Typescript Tooling Config",{"key":112,"name":113,"count":11},"typescript-type-fundamentals","Typescript Type Fundamentals",{"key":115,"name":116,"count":11},"vue-components-props","Vue Components Props",{"key":118,"name":119,"count":11},"vue-composition-api","Vue Composition Api",{"key":121,"name":122,"count":11},"vue-directives-templates","Vue Directives Templates",{"key":124,"name":125,"count":11},"vue-performance-testing","Vue Performance Testing",{"key":127,"name":128,"count":11},"vue-reactivity-system","Vue Reactivity System",{"key":130,"name":131,"count":11},"vue-router-state-management","Vue Router State Management",{"key":8,"name":9,"count":11},[134,138,141,144,147],{"key":135,"name":136,"count":137},"angular","Angular",450,{"key":139,"name":140,"count":137},"javascript","JavaScript",{"key":142,"name":143,"count":137},"react","React",{"key":145,"name":146,"count":137},"typescript","TypeScript",{"key":148,"name":149,"count":137},"vue","Vue",[151,169,183,196,209,222],{"id":152,"topic":9,"difficulty":153,"body":154,"options":155,"correct_key":163,"explanation":168},"019f56bb-bab6-7438-9aea-20f04158f6ec",1,"What is a cross-site scripting (XSS) vulnerability?",[156,159,162,165],{"key":157,"text":158},"a","A server crashing because a page sends far too many requests at once",{"key":160,"text":161},"b","A visitor tricking a site into serving an outdated cached copy of a page",{"key":163,"text":164},"c","An attacker getting a victim's browser to run malicious script from a page",{"key":166,"text":167},"d","A slow network connection that makes a page's own scripts load in the wrong order and fail","XSS means attacker-controlled script executes in the victim's browser in the context of a trusted site, letting it steal cookies\u002Ftokens, read the DOM, or act as the user. It is a client-side code-execution flaw, not a server crash (a) or a caching issue (b).",{"id":170,"topic":9,"difficulty":171,"body":172,"options":173,"correct_key":157,"explanation":182},"019f56bb-bab6-7a6e-9413-4aa8961b631d",2,"```\nconst comment = getUserComment();   \u002F\u002F text typed by any visitor\ndocument.getElementById(\"box\").innerHTML = comment;\n```\nA comment field renders each visitor's text with the code above. Why is this dangerous?",[174,176,178,180],{"key":157,"text":175},"A comment containing markup like `\u003Cimg src=x onerror=...>` will be parsed and executed",{"key":160,"text":177},"`innerHTML` shows only plain text, so any HTML tag in the comment crashes the page",{"key":163,"text":179},"Assigning to `innerHTML` is not supported in modern browsers and silently fails",{"key":166,"text":181},"Search engines cannot index text set this way, but there is otherwise no real security problem here","Assigning untrusted text to `innerHTML` makes the browser parse it as HTML, so an attacker can inject an image with an `onerror` handler (or other markup) that runs script — stored XSS. `innerHTML` does render HTML rather than showing it as text (b), which is exactly the danger. Use `textContent`, or sanitize if HTML is genuinely required.",{"id":184,"topic":9,"difficulty":171,"body":185,"options":186,"correct_key":166,"explanation":195},"019f56bb-bab7-72da-bf42-b26c6ea9f8d8","What distinguishes a stored XSS from a reflected XSS?",[187,189,191,193],{"key":157,"text":188},"Stored XSS only works over plain HTTP, while reflected XSS needs an HTTPS connection",{"key":160,"text":190},"Reflected XSS can read cookies and tokens, whereas stored XSS is unable to touch them",{"key":163,"text":192},"Stored XSS executes on the server side, whereas reflected XSS executes in the browser",{"key":166,"text":194},"Stored XSS is saved server-side and shown to later visitors; reflected XSS bounces back in the response to a crafted request","Stored (persistent) XSS lives in the app's data — a comment, a profile field — and fires for everyone who loads it; reflected XSS is not stored but echoed straight back from a single crafted request or link. Both run in the browser (c) and both can read cookies (b); the axis is where the payload lives, not what it can do.",{"id":197,"topic":9,"difficulty":171,"body":198,"options":199,"correct_key":160,"explanation":208},"019f56bb-bab7-7bad-9dce-1b124a674732","```\nconst name = getQueryParam(\"name\");   \u002F\u002F attacker controls the URL\n\u002F\u002F Option A:\nbox.innerHTML = \"Hello \" + name;\n\u002F\u002F Option B:\nbox.textContent = \"Hello \" + name;\n```\nBoth lines show the visitor's name. Which is the safe choice for untrusted input, and why?",[200,202,204,206],{"key":157,"text":201},"Option A, because `innerHTML` automatically escapes any dangerous characters on its own",{"key":160,"text":203},"Option B, because `textContent` inserts the value as literal text, not as HTML",{"key":163,"text":205},"Either one, since a URL query parameter cannot contain real HTML tags",{"key":166,"text":207},"Neither; the only safe way is to disable JavaScript for the whole page","`textContent` sets the node's text and never parses markup, so `\u003Cscript>` becomes visible characters instead of executing. `innerHTML` parses the string as HTML, so an attacker-controlled `name` can inject script; it does not auto-escape (a). URL parameters can absolutely carry HTML\u002FJS payloads (c).",{"id":210,"topic":9,"difficulty":153,"body":211,"options":212,"correct_key":157,"explanation":221},"019f56bb-bab8-7383-8a1d-99f41138c470","Why should user-provided values be escaped (output-encoded) before being placed into a page's HTML?",[213,215,217,219],{"key":157,"text":214},"So characters like `\u003C` and `>` are shown as text instead of being read as HTML tags",{"key":160,"text":216},"So the page loads faster because the browser then has less HTML to parse",{"key":163,"text":218},"So the values are compressed and take up less space in the HTTP response",{"key":166,"text":220},"So screen readers can pronounce the special characters more accurately","Escaping turns HTML-significant characters (`\u003C`, `>`, `&`, quotes) into harmless entities, so the browser renders them as text and cannot be tricked into treating injected markup as real tags — the core defense against XSS. It is about safety, not performance (b) or size (c).",{"id":223,"topic":9,"difficulty":171,"body":224,"options":225,"correct_key":166,"explanation":234},"019f56bb-bab8-78fe-9a91-f9d67e3f7485","Most UI frameworks offer a special way to insert a raw HTML string into the DOM (for example a \"render raw HTML\" binding). What is the main security concern when using such a feature with data that came from users?",[226,228,230,232],{"key":157,"text":227},"It disables the browser's back button for as long as the raw HTML stays on screen",{"key":160,"text":229},"It always makes the component re-render noticeably slower than normal bindings do",{"key":163,"text":231},"It converts the incoming HTML to plain text, so the intended formatting is lost",{"key":166,"text":233},"It bypasses the framework's automatic escaping, so any script in the data can run","Frameworks escape interpolated values by default; the raw-HTML binding deliberately turns that off and injects the string as markup, so feeding user data into it reintroduces XSS unless the HTML is sanitized first. It does not convert HTML to text (c) — that would actually be the safe, default behavior.",{"fields":236,"seniorities":410,"interview_shapes":411,"locales":416,"oauth":418,"question_count":421,"coach_enabled":422,"jd_match_enabled":422},[237,262,270,287,311,324,343,362,384,391,397,404],{"key":238,"name_tr":239,"name_en":239,"sort":153,"specializations":240},"backend","Backend",[241,244,247,250,253,256,259],{"key":242,"name":243,"field":238},"general","Genel",{"key":245,"name":246,"field":238},"go","Go",{"key":248,"name":249,"field":238},"python","Python",{"key":251,"name":252,"field":238},"java","Java",{"key":254,"name":255,"field":238},"csharp","C#\u002F.NET",{"key":257,"name":258,"field":238},"nodejs","Node.js",{"key":260,"name":261,"field":238},"php","PHP",{"key":5,"name_tr":6,"name_en":6,"sort":171,"specializations":263},[264,265,266,267,268,269],{"key":242,"name":243,"field":5},{"key":139,"name":140,"field":5},{"key":145,"name":146,"field":5},{"key":142,"name":143,"field":5},{"key":148,"name":149,"field":5},{"key":135,"name":136,"field":5},{"key":271,"name_tr":272,"name_en":272,"sort":273,"specializations":274},"fullstack","Fullstack",3,[275,276,277,278,279,280,281,282,283,284,285,286],{"key":242,"name":243,"field":271},{"key":245,"name":246,"field":238},{"key":248,"name":249,"field":238},{"key":251,"name":252,"field":238},{"key":254,"name":255,"field":238},{"key":257,"name":258,"field":238},{"key":260,"name":261,"field":238},{"key":139,"name":140,"field":5},{"key":145,"name":146,"field":5},{"key":142,"name":143,"field":5},{"key":148,"name":149,"field":5},{"key":135,"name":136,"field":5},{"key":288,"name_tr":289,"name_en":289,"sort":290,"specializations":291},"devops-cloud","DevOps \u002F Cloud",4,[292,293,296,299,302,305,308],{"key":242,"name":243,"field":288},{"key":294,"name":295,"field":288},"aws","AWS",{"key":297,"name":298,"field":288},"gcp","GCP",{"key":300,"name":301,"field":288},"azure","Azure",{"key":303,"name":304,"field":288},"kubernetes","Kubernetes",{"key":306,"name":307,"field":288},"terraform","Terraform",{"key":309,"name":310,"field":288},"linux","Linux",{"key":312,"name_tr":313,"name_en":313,"sort":314,"specializations":315},"ai-engineer","AI Engineer",5,[316,317,318,321],{"key":242,"name":243,"field":312},{"key":248,"name":249,"field":312},{"key":319,"name":320,"field":312},"llm-rag","LLM\u002FRAG",{"key":322,"name":323,"field":312},"mlops","MLOps",{"key":325,"name_tr":326,"name_en":327,"sort":328,"specializations":329},"database","Veritabanı","Database",6,[330,331,334,337,340],{"key":242,"name":243,"field":325},{"key":332,"name":333,"field":325},"postgresql","PostgreSQL",{"key":335,"name":336,"field":325},"mysql","MySQL",{"key":338,"name":339,"field":325},"mongodb","MongoDB",{"key":341,"name":342,"field":325},"redis","Redis",{"key":344,"name_tr":345,"name_en":346,"sort":347,"specializations":348},"mobile","Mobil","Mobile",7,[349,350,353,356,359],{"key":242,"name":243,"field":344},{"key":351,"name":352,"field":344},"ios-swift","iOS (Swift)",{"key":354,"name":355,"field":344},"android-kotlin","Android (Kotlin)",{"key":357,"name":358,"field":344},"flutter","Flutter",{"key":360,"name":361,"field":344},"react-native","React Native",{"key":363,"name_tr":364,"name_en":365,"sort":366,"specializations":367},"security","Güvenlik","Security",8,[368,369,372,375,378,381],{"key":242,"name":243,"field":363},{"key":370,"name":371,"field":363},"appsec","AppSec",{"key":373,"name":374,"field":363},"offensive-pentest","Offensive \u002F Pentest",{"key":376,"name":377,"field":363},"cloud-security","Cloud Security",{"key":379,"name":380,"field":363},"devsecops","DevSecOps",{"key":382,"name":383,"field":363},"blue-team-incident","Blue Team \u002F Incident",{"key":385,"name_tr":386,"name_en":387,"sort":388,"specializations":389},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[390],{"key":242,"name":243,"field":385},{"key":392,"name_tr":393,"name_en":393,"sort":394,"specializations":395},"data-engineer","Data Engineer",10,[396],{"key":242,"name":243,"field":392},{"key":398,"name_tr":399,"name_en":400,"sort":401,"specializations":402},"game-dev","Oyun Geliştirme","Game Development",11,[403],{"key":242,"name":243,"field":398},{"key":405,"name_tr":406,"name_en":406,"sort":407,"specializations":408},"ml-engineer","ML Engineer",12,[409],{"key":242,"name":243,"field":405},[14,15,16],{"junior":412,"mid":414,"senior":415},{"questions":413,"median_sec":3},20,{"questions":413,"median_sec":3},{"questions":413,"median_sec":3},[417,10],"tr",[419,420],"google","github",21750,true]