Hands On: Security in Angular Applications training
Hands On: Security in Angular Applications Intensive Training
Hands On: Security in Angular Applications
  • Learn to recognise and defend against real attack vectors such as XSS, CSRF and injection
  • Implement OAuth 2.x and the Backend-For-Frontend (BFF) pattern securely
  • 100% hands-on: integrate security tests directly into your development process
Angular.DE
Official German Community

No public dates currently available.

Request In-House Now
Lifetime access to all materials incl. updates
5 half days
Duration
95%
Recommendation Rate
Over 8.558 participants from leading companies learn with workshops.de
Logo of RWE Group Business Services GmbH, Dortmund
Logo of Generali
Logo of Allianz
Logo of adesso AG, Dortmund
Logo of Commerzbank AG, Frankfurt
Logo of Robert Bosch GmbH, Stuttgart
Logo of Pass Consulting Group
Logo of RWE Group Business Services GmbH, Dortmund
Logo of Generali
Logo of Allianz
Logo of adesso AG, Dortmund
Logo of Commerzbank AG, Frankfurt
Logo of Robert Bosch GmbH, Stuttgart
Logo of Pass Consulting Group

Hands On: Security in Angular Applications Intensive Training

Advanced · 5 half days or flexible as in-house training · In-House

60% Hands-on Practice
Exercises with real projects from everyday development
Certified Trainers
Google Developer Experts & Community Experts
Bonus: Lifetime Access
Materials stay up to date — even after the workshop

In this hands-on workshop, you'll learn how to systematically secure Angular applications against real-world attack vectors. You'll work with actual attack scenarios, analyze vulnerable code examples, and gain an in-depth understanding of the security mechanisms that Angular and modern browsers provide.

The focus is on the topics that most frequently lead to security incidents in practice: Cross-Site Scripting (XSS), Content Security Policy (CSP), secure token management in the browser, OAuth 2.x and OpenID Connect, as well as the Backend-For-Frontend (BFF) pattern as an architectural answer to the security limitations of SPAs.

By the end of the workshop, you'll not only know what the vulnerabilities are, but how to reliably detect, prevent, and test them in your own Angular projects.


Agenda

Logo

Browser Security Fundamentals & Same Origin Policy

  • Same Origin Policy and CORS: fundamentals and configuration
  • How browsers isolate content and where the limits are
  • Dealing with malicious JavaScript in the browser
  • Overview of typical attack vectors against Angular applications
  • Hands-on: analyzing vulnerabilities in the browser DevTools

Logo

Cross-Site Scripting (XSS) in Angular

  • How Angular prevents XSS attacks by default – and when it fails
  • Using the DomSanitizer correctly: using bypassSecurityTrust* safely
  • Typical XSS pitfalls in Angular templates, routing and third-party libraries
  • Enabling and configuring Trusted Types in Angular
  • Hands-on: attacking and securing a vulnerable Angular app

Logo

Content Security Policy (CSP)

  • What CSP does – and what it doesn't
  • CSP directives in detail: script-src, style-src, connect-src and more
  • Common mistakes in CSP configurations and how you avoid them
  • Implementing a strict CSP with nonces for Angular applications
  • Integrating and testing CSP in the Angular build process
  • Hands-on: configuring and debugging a CSP policy for an Angular application

Logo

Secure Token Management & OAuth 2.x

  • Security risks of storing tokens in the browser (localStorage, sessionStorage, cookies)
  • OAuth 2.0/2.1 and OpenID Connect: fundamentals and security implications
  • The PKCE flow and why it is mandatory for SPAs
  • Security recommendations for using OAuth 2.x directly in Angular
  • Hands-on: implementing an OAuth 2.x flow securely in Angular

Logo

Backend-For-Frontend (BFF) Pattern

  • Why SPAs have structural security limits with OAuth
  • The BFF pattern as an architectural answer: concept and benefits
  • Server-side token handling: cookies vs. bearer tokens
  • When is the BFF effort worth it – and when is it not?
  • Hands-on: securing an Angular app with a BFF backend

Logo

Vulnerability Scanning & Security in the Development Process

  • Static analysis: ESLint security plugins, npm audit, Snyk
  • Dynamic analysis: an overview of OWASP ZAP and other tools
  • Integrating security tests into CI/CD pipelines
  • OWASP Top 10 for Angular developers
  • Wrap-up: checklist for secure Angular applications & next steps

What you should know

Prerequisites
  • Basic Angular knowledge – you should already have developed your own Angular applications
  • TypeScript knowledge – confident use of TypeScript is required
  • Basic understanding of HTTP – how requests, responses, headers and cookies work
  • Development environment: Node.js (current LTS), Angular CLI and an editor (VS Code recommended) should be installed

Prior knowledge of web security is helpful, but not required. All security concepts are introduced in the workshop.

Target Audience

The course “Hands On: Security in Angular Applications” is aimed at Advanced.


What's Included

Certificate of Participation
Shareable on LinkedIn Logo
Virtual classroom
Interactive learning platform with exercises and materials
Bonus
Lifetime Access
Including updates to training materials
In-House/Corporate Seminars
Customized adaptations available
On-site at your location or online
Available in German and English

Request in-house/corporate training

Interested in an in-house Hands On: Security in Angular Applications training for your team or company?
Submit a request and book a preliminary meeting with our advisor.
Tailored training to your needs
On-site or remote for multiple employees
German and English available
Robin Böhm, CEO of workshops.de
Robin Böhm
CEO of workshops.de

What our participants say

Profile picture of Oleg Varaksin
Oleg Varaksin
Senior Software Engineer / Consultant

Attended Angular & Agentic AI Engineering Intensive Training

Profile picture of Florian Pauly
Florian Pauly
Junior Software Developer

Attended Angular & TypeScript Intensive Training

Profile picture of Thomas Stolz
Thomas Stolz
IT Application Manager Development

Attended Angular & TypeScript Intensive Training

Participant illustration
Anonymized on request
Participant

Attended Angular Advanced: Architecture, Quality & Mono-Repositories Intensive Training

Participant illustration
Anonymized on request
Participant

Attended Angular & TypeScript Intensive Training

Profile picture of Maximilian Boll
Maximilian Boll
Participant

Attended Angular & TypeScript Intensive Training

Questions and answers

Our public Hands On: Security in Angular Applications remote courses take place from 9:00 AM to 1:00 PM, on-site Hands On: Security in Angular Applications trainings from 9:00 AM to 4:30 PM.

For in-house seminars, individual adjustments are possible.

Yes. At the end of each of our Hands On: Security in Angular Applications seminars, participants receive a signed certificate of attendance.

The certificate includes a verification URL and can be shared on your LinkedIn profile. Learn more about managing certificates on LinkedIn.

Yes, we offer our Hands On: Security in Angular Applications seminars in German and English.

Public dates are held in German, unless explicitly stated otherwise.

In-house seminars can be conducted in the desired language.

All materials and exercises are fully available in English.

Yes. We offer our Hands On: Security in Angular Applications seminars both remotely and on-site. Thanks to our virtual classroom, you can conveniently participate in our workshops from anywhere. Our online presentations are regularly updated, and you have permanent access after the training. Exercises can be accessed and unlocked through an online interface, and we have added additional tasks to prepare you for remote workshops.

We also offer in-house seminars and public trainings on-site. In our schedule overview, you can see the respective venue of the trainings. For in-house trainings, we are happy to discuss the venue details individually with you.

For public Hands On: Security in Angular Applications seminars, we use the online meeting tool Zoom alongside our classroom.
A test link is also included in the preparation to let you try out the technology. The remote workshop is designed so that everyone works from different locations with their own computer.

For in-house seminars, we can conduct the meeting via Zoom or Microsoft Teams.
Other meeting software may be used by arrangement.

In-house Hands On: Security in Angular Applications trainings: Individual consulting with code mentoring

For our in-house seminars, we additionally offer code mentoring.

What is code mentoring?

  • Ask-Me-Anything sessions: Clarify questions and uncertainties from the course directly with an expert.
  • Code review: Submit your own code snippets and have them analyzed and evaluated by experts.
  • Advanced topics: Ask in-depth questions about the course topic to expand your knowledge.
Public Hands On: Security in Angular Applications trainings: Exchange on our community Discord

For participants of public trainings, we recommend joining our community Discord server.

Your benefits on Discord:

  • Diverse channels for questions and discussions – beyond the course topic.
  • An engaged community that supports you in learning.

Yes. You can enter your routing ID directly in our order form. Our invoices are sent as ZUGFeRD PDFs right after booking.
If you have provided a routing ID, our team will be notified and we will handle the upload to the portal. If we need additional information, we will contact you after booking.

Team profile pictures
Still have questions?

Just send us an email. If you prefer a more personal contact, Britta is also happy to receive a call from you!

Weekdays from 8 AM to 1 PM

info@workshops.de

+49 30 / 75437336

In-House Training
Individual Pricing
Inquire Now