What is the standard reference for DOM mastery?
The idea is: stipulate that no attacker can ever inject Javascript into a browser. Assume we solve that problem completely. Now, how secure are DOM-based applications? Turns out: not that much more secure. Lots of very clever examples.
(Also, anything icamtuf touches is probably going to be good.)