Engineering · Security
Security
2 write-ups on security.
- Authorisation belongs in two placesFinding and closing broken object-level authorisation across six subsystems of a growing API — why the route layer alone isn't enough, and what makes these bugs so easy to ship.
- The endpoint that sends an SMS to anyone who asksAny unauthenticated endpoint that triggers a real-world action is an abuse vector. Layered rate limiting, a challenge, and the tracking you need to enforce either.