Build Next.js & Express middleware using Sec-Fetch-Site, Mode, and Dest headers to eliminate CSRF and XS-Leaks.
Execution runs 100% locally inside the browser sandbox using HTML5 Canvas, Web Cryptography Subtle API, and Web Workers. Zero egress.
Zero network latency. Operates completely offline with zero dependencies on third-party backend servers or cloud services.
Built according to official RFC specifications, cryptographic test vectors, and enterprise-grade data transformation standards.
Toggle same-site only, top-level navigations, and image exemptions.
Review the TypeScript request isolation function.
Integrate into your Next.js middleware.ts or Express server.
Sec-Fetch-Site indicates the relationship between the initiator's origin and the target origin (same-origin, same-site, cross-site, none).
Resource isolation via Sec-Fetch metadata provides powerful defense-in-depth that can prevent unauthorized cross-origin requests at the gateway.
Zero-egress companion tools in the Security & Network suite
Audit CSP, HSTS, X-Frame-Options, and security headers with OWASP grading (A+ to F).
Measure cryptographic randomness, Shannon entropy (0-8 bits/byte), Chi-square test, and byte distributions.
Generate secure RFC 6238 Base32 TOTP secret keys and standard otpauth:// URIs for Google Authenticator.
Construct and validate HTTP CSP headers and meta tags.