I think the JavaScript world has given up on all of these secure behaviors a long time back. Just look at Next.js