VOOZH about

URL: https://thenewstack.io/how-to-secure-web-applications-in-a-static-and-dynamic-world/

⇱ How to Secure Web Applications in a Static and Dynamic World - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2021-03-03 13:29:35
How to Secure Web Applications in a Static and Dynamic World
podcast,sponsor-okta,sponsored,sponsored-podcast,the-new-stack-makers,
API Management / Security / Serverless

How to Secure Web Applications in a Static and Dynamic World

Netlify's Dustin Rogers, staff application security engineer, talks about all things related to static Web security management.
Mar 3rd, 2021 1:29pm by Alex Williams and B. Cameron Gain
👁 Featued image for: How to Secure Web Applications in a Static and Dynamic World
Okta sponsored this post.

Okta sponsored this podcast.

Netlify is a popular static “Jamstack” website-hosting platform used by over a million web developers. But while Netlify is popular thanks to its simplicity, the security it offers for the static environments is of interest as well.

Web security is the theme of the latest episode in our new series “Security @ Scale” on The New Stack Makers with Okta. The series explores security in modern environments with stories from the trenches including security horror stories and fantastic failures.

In this episode, co-hosts Alex Williams, founder and publisher of The New Stack, and Randall Degges, head of developer advocacy at security services provider Okta, speak with guest Dustin Rogers, staff application security engineer, Netlify, about all things related to static web security management.

Okta, Inc. is The World’s Identity Company™. We secure Identity, so everyone is free to safely use any technology. Our customer and workforce solutions empower businesses and developers to use the power of Identity to drive security, efficiencies, and success.
Learn More
The latest from Okta

Degges noted static websites help organizations avoid much security- and other operations-related problems, and thus require less maintenance. Rogers agreed, noting that while many security best practices apply to both static and dynamic website management, Netlify can do much of the heavy lifting for DevOps teams, such as header management.


Okta Series – How to Secure Web Applications in a Static and Dynamic World w/ Dustin Rogers

The developer is ultimately responsible for security. Static websites, for example, while requiring less security maintenance and posing fewer potential vulnerabilities than dynamic websites do, still must be maintained. “I just want to make sure it’s said that security can still fall to the developer, even in the Jamstack world,” said Rogers. “But we like to think that these are made easier.”

At the same time, static sites are also typically not completely static, either. Typical “dynamic things that people want to do,” include adding forum data and forum-information storage and “pulling in information from external APIs, such as databases wrapped with APIs or pseudo database interaction,” said Rogers.

“These are some of the ways people are pulling in dynamic data into their Jamstack sites,” said Rogers.

Dynamic JavaScript (JS) frameworks, including React, can offer a number of advantages in this context. “I think the big advantage of dynamic JS frameworks, such as React, is the ability to reuse the JS code,” said Rogers. “So, it’s bundled, and we see a decrease in size, making it easier to render. This is especially true for mobile apps, because mobile environments are lighter-weight generally, and need the speed to process.”

Some of the security risks developers might make on a static website, such as with Netlify’s platform, including the use of sensitive values that remain unencrypted as query parameters.

“For years, I was starting to see less of this, but now I feel like I’m seeing it more — at a minimum, placing these inside a post form makes more sense, I think. But the reason I think people are using query parameters often has to do with portability — clickable URLs, such as those sent in marketing emails,” said Rogers. “We guarantee cache-control… but if a value is sensitive, you want, as the developer, to protect it as much as possible. That’s one thing that I see quite often that I cringe at.”

Okta, Inc. is The World’s Identity Company™. We secure Identity, so everyone is free to safely use any technology. Our customer and workforce solutions empower businesses and developers to use the power of Identity to drive security, efficiencies, and success.
Learn More
The latest from Okta
TRENDING STORIES
Alex Williams is founder and publisher of The New Stack. He's a longtime technology journalist who did stints at TechCrunch, SiliconAngle and what is now known as ReadWrite. Alex has been a journalist since the late 1980s, starting at the...
Read more from Alex Williams
BC Gain is founder and principal analyst for ReveCom Media. His obsession with computers began when he hacked a Space Invaders console to play all day for 25 cents at the local video arcade in the early 1980s. He then...
Read more from B. Cameron Gain
Okta sponsored this post.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Pragma.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.