Don't forget about 25% off Laravel Security in Depth 😁
One last reminder about our Black Friday sale on Laravel Security in Depth subscriptions.
 
    One last reminder about our Black Friday sale on Laravel Security in Depth subscriptions.
 
     
            [Tip #123] If an API client tries to connect via unencrypted HTTP, what should your API do: redirect to HTTPS, disable HTTP, offer a swift rebuke, or take matters into it's own hands?
 
            [Tip #122] Content Security Policies are awesome, but if you haven't fully configured all of your directives, it's possible to redirect requests, inherit Nonces, and get juicy CSP-bypassing XSS! 😈
 
            [Tip #121] Technically, XSS involves injecting malicious Javascript, but sometimes you don't need any JS to get up to mischief! 😈
 
            I almost missed it, but it's time to celebrate 4 years of Securing Laravel!