Web Application
Fields: Security, Accessibility ยท Also called: web app
A web application is software that runs on a web server and that users interact with through a web browser, over a network such as the internet or an intranet. It commonly stores its data in a database on the server side.
Distinctions
- Versus website. In the early web, a website was largely a collection of pages, the domain of web design and webmastering. A web application is software that does something for its user, such as processing a transaction or managing an account, and typically keeps its state in a database. The line blurred as websites became dynamic, but it persists in security practice, where web applications are assessed as software with their own classes of vulnerability, as in the OWASP Top 10.
- Versus frontend web application. The definition above centers on software running on a web server. A frontend web application instead does much of its work in the browser, depending on browser features such as JavaScript to render the interface and fetch data. A common form is the single-page application, which MDN describes as a web app implementation that “loads only a single web document, and then updates the body content of that single document via JavaScript APIs such as Fetch when different content is to be shown.” Many web applications combine both approaches.
- Versus WebAssembly. WebAssembly (Wasm), which MDN describes as “a low-level assembly-like language that brings near-native performance to the web,” lets code compiled from languages such as C, C++, C#, and Rust run in the browser. That reaches well beyond a typical web application. The v86 project, for example, emulates an x86 PC in the browser by translating machine code to WebAssembly at runtime, and can boot operating systems including Linux, FreeBSD, and several versions of Windows.
Accessibility requirements
A web application is both ICT and web content, so accessibility law reaches it the same way it reaches a website.
- ADA Title II. 28 CFR ยง 35.104 defines web content as “the information and sensory experience to be communicated to the user by means of a user agent, including code or markup that defines the content’s structure, presentation, and interactions.” A web application that a state or local government provides is web content, and 28 CFR ยง 35.200 requires it to comply with WCAG 2.1 Level A and Level AA.
- Section 508. Federal agencies’ electronic content is held to WCAG 2.0 Level A and Level AA under the revised Section 508 Standards.
Meeting WCAG is conformance; whether an entity is compliant also depends on the law that applies to it. See Conformance vs. Compliance.
History
Early interactive features on websites, such as form handling, were typically separate programs invoked through the Common Gateway Interface (CGI), a specification written at the National Center for Supercomputing Applications (NCSA) in 1993 and later documented as RFC 3875. The web server handed each request to a program, often kept in a cgi-bin directory, which generated the response. Such programs were often written in C, and Perl, whose version 5 was released in 1994, gained widespread popularity in the mid-1990s as a CGI scripting language. Server-side technologies that embedded program logic in server-rendered pages, such as PHP 3 (released in June 1998, and itself descended from a 1994 set of CGI programs), Microsoft’s Active Server Pages (ASP), JavaServer Pages (JSP), and ColdFusion, made it practical to build entire interactive services this way, and the term web application came into common use alongside them.
Full-stack web application frameworks followed. ASP.NET shipped as part of Microsoft’s .NET Framework 1.0 in 2002. Ruby on Rails was first released as open source in July 2004 and reached version 1.0 in December 2005. Built around the model-view-controller pattern and convention over configuration, it influenced web application frameworks in other languages, and in August 2006 Apple announced that it would ship Rails with Mac OS X 10.5.
By 2000, the term was established enough to be used without definition in technical specifications. The Java SIP Servlet API Specification (MCI WorldCom, revision 0.5, 2000), based on Sun Microsystems’ Java Servlet Specification 2.2, refers to the tools “necessary to deploy web applications” and to a developer’s files “for the web application.”
The term was in use before its appearances on this site. It appears here in Business Analysis of Web Application Information (Rietta, 2005), which describes web applications as “delivered to users from a web server over a network such as the internet or an intranet,” and in AppSec as a Requirement in the Development Process (Rietta, 2020).
Sources
- RFC 3875: The Common Gateway Interface (CGI) Version 1.1, IETF, October 2004. Retrieved September 28, 2026.
- Java SIP Servlet API Specification, revision 0.5, Ajay P. Deo, Kelvin R. Porter, and Mark X. Johnson, MCI WorldCom, 2000; hosted by Columbia University. Retrieved September 28, 2026.
- Common Gateway Interface, Wikipedia. Retrieved September 28, 2026.
- Perl, Wikipedia. Retrieved September 28, 2026.
- History of PHP, The PHP Group. Retrieved September 28, 2026.
- OWASP Top Ten, OWASP Foundation. Retrieved September 28, 2026.
- .NET Framework, Wikipedia. Retrieved September 28, 2026.
- Ruby on Rails, Wikipedia. Retrieved September 28, 2026.
- SPA (Single-page application), MDN Web Docs. Retrieved September 28, 2026.
- WebAssembly, MDN Web Docs. Retrieved September 28, 2026.
- v86: x86 PC emulator and x86-to-wasm JIT, running in the browser, GitHub. Retrieved September 28, 2026.
- 28 CFR ยง 35.104 Definitions, Legal Information Institute, Cornell Law School. Retrieved September 28, 2026.
- 28 CFR ยง 35.200 Requirements for web and mobile accessibility, Legal Information Institute, Cornell Law School. Retrieved September 28, 2026.
- Information and Communication Technology (ICT) Standards and Guidelines (Revised Section 508 Standards), U.S. Access Board. Retrieved September 28, 2026.