Cross-Site Scripting (XSS) and is your SPA really safe from it?
Secure Cookies in 5 steps
CSRF tokens for SPAs
Demystifying CORS, CSRF tokens, SameSite & Clickjacking - Web Security