Answer
Major risks include:
- XSS – rely on Angular sanitization, avoid bypassSecurityTrust.
- CSRF – use server-issued anti-forgery tokens or HttpOnly cookies.
- Sensitive data exposure – never store secrets in the frontend.
- Clickjacking – enforce frame-ancestors policies on server.
- API abuse – ensure backend role validation and rate limiting.