ALL LESSONSWEEK 47SUNDAY

RETRIEVE · PERFORMANCE, SECURITY + ACCESSIBILITY

Threat-model and repair them

Security follows trust boundaries30–60 MINUTESCORE + PRACTICAL
01

GROUND

Problem

What becomes confusing, fragile, or impossible without understanding threat-model and repair them? This lesson answers that through explanation, a worked example, two runnable exercises, and a reference solution. No teacher-supplied worksheet is required.

Performance, security, and accessibility became disciplines because functional software can still exclude, leak, stall, or harm.
02

LEARN

Concept explanation

Threat-model and repair them belongs to “Security follows trust boundaries”. threat-model and repair them is retrieval day: rebuild core behavior without notes, then compare evidence and teach corrections.

For threat-model and repair them, trace concrete input, state transition, output, and failure through a system invariant made testable through budgets, trust boundaries, semantic interfaces, and controlled failure.

Quality emerges from system invariants: bounded work, controlled authority, explicit trust, semantic interfaces, and observable failure. Apply that model to supplied normal, boundary, and failure cases; each case below names its input and expected evidence.

Observable

Evidence produced by the threat-model and repair them experiment: output, state, trace, bytes, timing, or diagnostics.

Invariant

Condition that must remain true while inputs or implementation of threat-model and repair them change.

Boundary

Point where threat-model and repair them crosses ownership, representation, time, process, network, or trust.

Example bank

Compare normal, boundary, failure, and cross-layer cases. Predict each observation before revealing the explanation.

Baseline · one variable

SETUPClose notes and recreate threat-model and repair them from blank starting state using: Build controlled XSS, CSRF, CORS, CSP, and SQL-injection lab using inert test payloads.

OBSERVERebuilt version reproduces Payload works only before defense; headers/queries/encoding prove least-authority repair.; correction log names every memory gap.

WHY IT MATTERSThis isolates the normal contract of threat-model and repair them; preserve its raw evidence as the control for every later comparison.

Boundary · same contract, harder input

SETUPWithout rereading, predict and handle: Map source, sink, principal, and trust decision for each.

OBSERVERecord what remains invariant and the first representation, owner, size, or timing value that changes in Chromium Performance · Memory · Accessibility · Security.

WHY IT MATTERSA boundary example is useful only when one named dimension changes and everything else stays comparable.

Failure · evidence before repair

SETUPDiagnose from memory, then consult reference only after capturing evidence: Demonstrate vulnerability locally, then apply contextual defense and regression test.

OBSERVECapture the first divergence from the baseline, including exact input, diagnostic, state, and recovery result. Expected recovery: Rebuilt version reproduces Payload works only before defense; headers/queries/encoding prove least-authority repair.; correction log names every memory gap.

WHY IT MATTERSThe diagnostic is part of the interface. Repair the proven cause, not the most visible symptom.

Cross-layer · follow ownership

SETUPTrace threat-model and repair them one layer below its usual abstraction through a system invariant made testable through budgets, trust boundaries, semantic interfaces, and controlled failure.

OBSERVECapture profiles, accessibility tree, keyboard order, security headers, trust boundaries, budgets, and recovery evidence.

WHY IT MATTERSThe lower layer is earned when it explains evidence the current layer cannot. Otherwise keep threat-model and repair them at the simpler boundary.

03

SEE

Worked example

Start from supplied index.html. Focus: Close notes and recreate threat-model and repair them from blank starting state using: Build controlled XSS, CSRF, CORS, CSP, and SQL-injection lab using inert test payloads.

  1. Run: Serve and open index.html; keyboard-activate the probe; inspect Performance, Accessibility, and Security panels.
  2. Save baseline evidence. Capture profiles, accessibility tree, keyboard order, security headers, trust boundaries, budgets, and recovery evidence.
  3. Boundary case: Without rereading, predict and handle: Map source, sink, principal, and trust decision for each.
  4. Failure case: Diagnose from memory, then consult reference only after capturing evidence: Demonstrate vulnerability locally, then apply contextual defense and regression test.
RESULT
Rebuilt version reproduces Payload works only before defense; headers/queries/encoding prove least-authority repair.; correction log names every memory gap. Starter-level baseline: Heading and button are keyboard reachable; activation updates announced output with a non-negative duration.
04

START HERE

Starter material

PREREQUISITESModern Chromium with Performance, Memory, Accessibility, and Security panels. Run security payloads only in supplied local fixtures.

ONE-TIME SETUPSave fixture files, run npx --yes serve ., then open the printed localhost URL.

Create index.html, paste this exact content, then run the command below.

<!doctype html>
<meta charset="utf-8">
<title>threat-model and repair them</title>
<main><h1>threat-model and repair them</h1><button id="probe">Run controlled probe</button><output id="result" aria-live="polite">Not run</output></main>
<script>
probe.addEventListener('click', () => {
  const start = performance.now();
  result.value = 'completed in ' + (performance.now() - start).toFixed(2) + 'ms';
});
</script>
RUNServe and open index.html; keyboard-activate the probe; inspect Performance, Accessibility, and Security panels.

STOP / CLEANUPClose recordings and press Ctrl+C in server terminal. Never aim controlled payloads at third-party systems.

05

DO WITH GUIDANCE

Guided exercise

Rebuild from memory: threat-model and repair them

  1. Normal case: Close notes and recreate threat-model and repair them from blank starting state using: Build controlled XSS, CSRF, CORS, CSP, and SQL-injection lab using inert test payloads.
  2. Write predicted evidence from this named case before running starter.
  3. Close notes, recreate core example, compare with reference, then explain corrections.
  4. Run exact normal case. Save commands, inputs, outputs, and diagnostics in notebook.
  5. Explain changed evidence using lesson mental model in no more than five sentences.
Concrete guided solution
  1. Copy the supplied index.html unchanged and run: Serve and open index.html; keyboard-activate the probe; inspect Performance, Accessibility, and Security panels.
  2. Write this prediction before inspecting output: Rebuilt version reproduces Payload works only before defense; headers/queries/encoding prove least-authority repair.; correction log names every memory gap.
  3. Perform only the named normal case: Close notes and recreate threat-model and repair them from blank starting state using: Build controlled XSS, CSRF, CORS, CSP, and SQL-injection lab using inert test payloads.
  4. Save the raw output, then annotate input → transition → evidence. Use Chromium Performance · Memory · Accessibility · Security to confirm the transition rather than inferring it.
  5. Compare prediction with evidence; if they differ, keep both and write the rule that explains the difference. Reference baseline: Heading and button are keyboard reachable; activation updates announced output with a non-negative duration.
06

DO ALONE

Independent exercise

Teach at three depths: threat-model and repair them

  1. Create second case from blank file: Without rereading, predict and handle: Map source, sink, principal, and trust decision for each.
  2. Then create controlled failure: Diagnose from memory, then consult reference only after capturing evidence: Demonstrate vulnerability locally, then apply contextual defense and regression test.
  3. Use Chromium Performance · Memory · Accessibility · Security to prove behavior, then repair controlled failure.
  4. Compare result against supplied acceptance checks and reference approach before marking complete.
Concrete independent solution
  1. Duplicate the starter into a clean comparison case; change only this boundary: Without rereading, predict and handle: Map source, sink, principal, and trust decision for each.
  2. Save its evidence beside the baseline and identify the first changed value. Capture profiles, accessibility tree, keyboard order, security headers, trust boundaries, budgets, and recovery evidence.
  3. Create the exact controlled failure: Diagnose from memory, then consult reference only after capturing evidence: Demonstrate vulnerability locally, then apply contextual defense and regression test.
  4. Write interface and expected evidence for threat-model and repair them from memory before creating implementation.
  5. Rebuild smallest baseline and run: Build controlled XSS, CSRF, CORS, CSP, and SQL-injection lab using inert test payloads.
  6. Add boundary and failure cases without notes: Map source, sink, principal, and trust decision for each. / Demonstrate vulnerability locally, then apply contextual defense and regression test.
  7. Compare against prior week artifact; record omissions and wrong assumptions.
  8. Correct, rerun until Payload works only before defense; headers/queries/encoding prove least-authority repair., then teach cause-and-effect at three depths.
  9. Rerun baseline, boundary, and repaired failure together. Accept only if all reproduce: Rebuilt version reproduces Payload works only before defense; headers/queries/encoding prove least-authority repair.; correction log names every memory gap.
07

COMPARE

Expected result

  • Rebuilt version reproduces Payload works only before defense; headers/queries/encoding prove least-authority repair.; correction log names every memory gap.
  • Heading and button are keyboard reachable; activation updates announced output with a non-negative duration.
  • Controlled threat-model and repair them failure produces captured evidence; repair restores stated invariant without hiding error.
08

PROVE

Acceptance checks

Lesson is complete only when every check is true. Each check is stored locally and travels with your JSON backup.

0/5 complete · saved on this device

09

UNSTICK

Hints

Reveal hints
  1. Start with supplied normal case exactly as written: Close notes and recreate threat-model and repair them from blank starting state using: Build controlled XSS, CSRF, CORS, CSP, and SQL-injection lab using inert test payloads.
  2. For boundary case, change only named dimension: Without rereading, predict and handle: Map source, sink, principal, and trust decision for each.
  3. If result is confusing, diff raw inputs and evidence before editing implementation.
  4. If tool shows nothing useful, move observation one boundary lower: representation, runtime, OS, or network.
10

VERIFY

Solution

Attempt both exercises before opening reference approach.

Reveal reference solution
  1. Run unmodified starter and preserve baseline evidence: Heading and button are keyboard reachable; activation updates announced output with a non-negative duration.
  2. Write interface and expected evidence for threat-model and repair them from memory before creating implementation.
  3. Rebuild smallest baseline and run: Build controlled XSS, CSRF, CORS, CSP, and SQL-injection lab using inert test payloads.
  4. Add boundary and failure cases without notes: Map source, sink, principal, and trust decision for each. / Demonstrate vulnerability locally, then apply contextual defense and regression test.
  5. Compare against prior week artifact; record omissions and wrong assumptions.
  6. Correct, rerun until Payload works only before defense; headers/queries/encoding prove least-authority repair., then teach cause-and-effect at three depths.
11

PREDICT · INSPECT · BREAK · DEBUG · MEASURE

Interrogate reality

Prediction: write expected output, state transition, ordering, and failure evidence before running either exercise.

Inspection: Use Performance and Memory profiles, Lighthouse carefully, accessibility tree, keyboard traversal, security headers, and controlled attack labs.

Measurement: Use budgets and distributions: Web Vitals, memory growth, attack surface, keyboard steps, contrast, error rates, and recovery time.

INSPECT

Capture raw evidence before explaining.

BREAK

Change one assumption and force controlled failure.

DEBUG

Find cause with Chromium Performance · Memory · Accessibility · Security before editing fix.

TOOL DRILL · keyboard only · record one retrievable command or shortcut
12

MASTERY + FRONTIER + BOUNDARY

Own the knowledge

TEACH

Explain threat-model and repair them at beginner, intermediate, and senior depth.

REBUILD

Recreate smallest useful example from blank file without notes or AI.

RETRIEVE

Schedule recall for day 1, 7, 30, and 90.

Creative frontier lab

Try first without opening the solutions. The constraints invite invention; the reference gives one concrete direction, never the only valid answer.

Constraint inversion

Re-solve threat-model and repair them by removing the most convenient abstraction. remove one risky or expensive capability, then measure what becomes simpler.

CONSTRAINTKeep the same inputs, observable result, and failure evidence; change the means, not the contract.

ORIGINAL IDEATurn subtraction into a design tool: the missing abstraction should reveal which responsibility it used to hide.

Reveal frontier solution
  1. Freeze the contract as three fixtures: Close notes and recreate threat-model and repair them from blank starting state using: Build controlled XSS, CSRF, CORS, CSP, and SQL-injection lab using inert test payloads. / Without rereading, predict and handle: Map source, sink, principal, and trust decision for each. / Diagnose from memory, then consult reference only after capturing evidence: Demonstrate vulnerability locally, then apply contextual defense and regression test.
  2. List every convenience used by the starter; remove the highest-level one while preserving Serve and open index.html; keyboard-activate the probe; inspect Performance, Accessibility, and Security panels..
  3. Implement the smallest replacement using remove one risky or expensive capability, then measure what becomes simpler.
  4. Run all fixtures and compare raw evidence. Keep the simpler version unless the removed abstraction has a demonstrated benefit.
Representation x-ray

Build an explanation artifact for threat-model and repair them: make the budget, trust boundary, ownership path, and semantic interface directly inspectable.

CONSTRAINTA peer must be able to locate the first divergence without reading implementation code.

ORIGINAL IDEATreat the explanation itself as a product: make invisible transitions visible, replayable, and diffable.

Reveal frontier solution
  1. Create one row or timestamped event for each transition in: Close notes and recreate threat-model and repair them from blank starting state using: Build controlled XSS, CSRF, CORS, CSP, and SQL-injection lab using inert test payloads.
  2. For every row record input, representation, owner, operation, output, and tool evidence from Chromium Performance · Memory · Accessibility · Security.
  3. Replay Without rereading, predict and handle: Map source, sink, principal, and trust decision for each.; highlight only changed rows.
  4. Replay Diagnose from memory, then consult reference only after capturing evidence: Demonstrate vulnerability locally, then apply contextual defense and regression test.; stop at the first divergent row and attach its recovery action.
Adversarial remix

Combine the boundary and failure into a new user-visible scenario for threat-model and repair them. build an adversarial fixture that tests slow, hostile, zoomed, keyboard-only, and failure states together.

CONSTRAINTDo not merely add more input. Invent a recovery interaction, alternate representation, or self-checking behavior.

ORIGINAL IDEAMake the system teach its own limits: the artifact should expose the invariant and offer a safe next action when it breaks.

Reveal frontier solution
  1. Combine these two pressures without changing them: Without rereading, predict and handle: Map source, sink, principal, and trust decision for each. AND Diagnose from memory, then consult reference only after capturing evidence: Demonstrate vulnerability locally, then apply contextual defense and regression test.
  2. Name the invariant that must survive and the user-visible evidence when it cannot: Rebuilt version reproduces Payload works only before defense; headers/queries/encoding prove least-authority repair.; correction log names every memory gap.
  3. Implement this original direction: build an adversarial fixture that tests slow, hostile, zoomed, keyboard-only, and failure states together.
  4. Demonstrate baseline, combined failure, recovery, then baseline again; save the sequence as a regression fixture.

Capability frontier

Push threat-model and repair them until another layer becomes justified. Record one robust technique, one contextual trade-off, and one labeled hack or historical curiosity.

CORE · PRACTICAL · CONTEXTUAL · HACK · FRAGILE · HISTORICAL · GOLF

Boundary

Tools identify signals, not intent. Passing audits cannot replace threat modeling, user testing, or architecture.

If this vanished tomorrow…

Use manual inspection, timing, logs, semantic documents, least privilege, and adversarial reasoning.

Why next layer is earned

System design is earned when local correctness must survive scale, failure, shared state, and evolving requirements.