"Where we're going, we don't need roads"... but we absolutely need better security. The 2025 incident caught us off guard because we had forgotten past lessons. In this talk, we revisit the evolution of threats, moving from the "XSS Hell" of 2013 to the intricate data leaks of the Server Component era.
We will break down exactly what happens when the boundary between server and client dissolves. We will discover when React still has our backs and when we’re the last line of defence. Instead of waiting for a crash, we will focus on prevention, using a "Shift Left" approach to find bugs early. We will implement concrete patterns like React Taint APIs and Defense in Depth. Join us to build a full toolkit and ensure history doesn't repeat itself in your application.
This talk has been presented at React Day Berlin 2026, check out the latest edition of this React Conference.























