<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>フロントエンドセキュリティ on and factory Tech Blog</title><link>https://andfactory.co.jp/techblog/tags/%E3%83%95%E3%83%AD%E3%83%B3%E3%83%88%E3%82%A8%E3%83%B3%E3%83%89%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3.html</link><description>Recent content in フロントエンドセキュリティ on and factory Tech Blog</description><generator>Hugo</generator><language>ja</language><lastBuildDate>Wed, 03 Jun 2026 15:00:00 +0900</lastBuildDate><atom:link href="https://andfactory.co.jp/techblog/tags/%E3%83%95%E3%83%AD%E3%83%B3%E3%83%88%E3%82%A8%E3%83%B3%E3%83%89%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3/index.xml" rel="self" type="application/rss+xml"/><item><title>Web アプリの XSS はどこから入るか — 4 つの侵入経路と多層防御モデル</title><link>https://andfactory.co.jp/techblog/posts/xss-attack-paths-multi-layer-defense.html</link><pubDate>Wed, 03 Jun 2026 15:00:00 +0900</pubDate><guid>https://andfactory.co.jp/techblog/posts/xss-attack-paths-multi-layer-defense.html</guid><description>XSS が今も現役な理由を、4つの侵入経路（Stored / Reflected / DOM-based / サプライチェーン・拡張機能）と多層防御モデル（CSP / レート制限 / トークン隔離 / 異常検知）で整理。better-auth の AT 保存設計を例に、攻撃経路 × 防御層のマトリクスで判断する考え方を示します。</description></item></channel></rss>