In Depth
In Depth: Three Reasonable Decisions, One Critical Vulnerability
[In Depth #41] What do you get when you combine an API, SameSite=None, and a Session cookie?
In Depth
[In Depth #41] What do you get when you combine an API, SameSite=None, and a Session cookie?
Security Tips
[Tip #123] If an API client tries to connect via unencrypted HTTP, what should your API do: redirect to HTTPS, disable HTTP, offer a swift rebuke, or take matters into it's own hands?
Security Tips
[Tip#70] This is your periodic reminder to check your app for any leaky APIs and fix them ASAP, otherwise you might end up with an email from Have I Been Pwned's Troy Hunt...