Skip to contentTopicsecurity
- Why Chrome Ignored My Automation Clicks (And Why It Was Right To)June 23rd, 2026
- What a Shallow Clone Taught Me About Pushing Security Patches SafelyJune 17th, 2026
- The Login That Looked Fine (And Had Two Invisible Holes)June 15th, 2026
- The Migration Comment That Almost Took Down Five Apps at OnceJune 15th, 2026
- The CSV Export That Could Have Run Code on Finance's LaptopJune 14th, 2026
- The Fixture Trap: How 113 Real Attendees Ended Up Committed to a Client RepoJune 14th, 2026
- Next.js Server Actions Aren't Protected — Until You Protect ThemJune 13th, 2026
- How a Security Audit Taught Me to Budget AI Costs in Code (Not Prompts)June 12th, 2026
- Fine-Grained RLS: Carving Memberships Out of Blanket Policy to Block Self-PromotionJune 11th, 2026
- Why I Replaced `===` With `timingSafeEqual` Across Every Cron RouteJune 10th, 2026
- The Silent Lockout: How Supabase's Auto-RLS Cost Me an Hour of Debugging the Wrong ThingJune 9th, 2026
- The Trusted Source That Still Bites You: SSRF on Shopify's Pagination HeaderJune 9th, 2026
- The One String I Forgot to Escape: AppleScript Injection in the iMessage BridgeJune 8th, 2026
- The Audit That Found Half My Action Files Completely UnvalidatedJune 7th, 2026
- CSV Formula Injection: Why 'Just Text' Isn'tJune 4th, 2026
- Every Document You Index Is Untrusted Input — Treat It That WayJune 4th, 2026
- How a USING (true) RLS Policy Left Every Shopify Order Open to Any Google AccountMay 30th, 2026
- How I Wired a Fillout Webhook Secret When Simple Mode Doesn't Do HeadersMay 29th, 2026
- Client-Side AES-256-GCM Is a Gate, Not a VaultMay 14th, 2026
- Your Middleware Isn't Enough: Mirror the Auth Check at the Route LayoutMay 14th, 2026
- Why I Stopped Validating at the Form and Started Doing It at the BoundaryMay 13th, 2026
- Why My Wildcard Sanitizer Had a Blind Spot (and How a %@% Fixed That)May 13th, 2026
- The XSS Vector Hiding in Your Database URLsMay 11th, 2026
- The Prompt Is Not a FirewallMay 5th, 2026
- How I Learned to Block the Call, Not Just Filter the OutputApril 30th, 2026
- The PII Leaks You Build YourselfApril 28th, 2026
- The Request Body That Could Empty Your AI BudgetApril 28th, 2026
- The .env File I Thought I Fixed Twice (And the One Command That Actually Works)April 26th, 2026
- How a Friendly Supabase Method Was Silently Injecting PostgreSQL WildcardsApril 25th, 2026
- How a Google API Error Ended Up in My UI (and What I Did About It)April 25th, 2026
- How a Default Next.js Setting Was Serving My Draft Posts to Anyone Who AskedApril 24th, 2026
- What CSP Taught Me About Third-Party Resource TypesApril 16th, 2026
- How I Hardened Apollo's Scanner Against Prompt Injection (Two Cheap Fixes That Actually Work)April 14th, 2026
- How My Own Robot Reviewer Caught My Secret Sitting in `ps aux`April 14th, 2026
- Validate Your Env Vars at Boot — or Pay the Price LaterApril 14th, 2026
- SQL Injection Was Hiding in My Supabase `.not('in')` CallsApril 13th, 2026
- The One-Liner That *Looked* Safe (and How an Origin Check Fixed It)April 13th, 2026
- How a Single String Was Gutting My Entire Content Security PolicyApril 9th, 2026
- The Auth Gate That Wasn't Guarding the Real DoorApril 6th, 2026
- An ID Is Not a Password: How We Closed an IDOR in Our Cancer Patient Chat AppApril 3rd, 2026
- How localStorage Bridged Sessions — And Then Became a Security HoleApril 3rd, 2026
- How an Open Redirect Hid Inside Our Next.js Server ActionsApril 2nd, 2026
- Page Auth Doesn't Guard Server Actions — Every Action Needs Its Own LockApril 2nd, 2026
- The Supabase Linter Warning That Silently Empties Your TablesApril 2nd, 2026
- Why I Stopped Trusting My Own FrontendApril 2nd, 2026