Api Credential Verification
Use before trusting a stored API key.
Authentication, secrets, authorization and hardening.
View all tagsUse before trusting a stored API key.
Use when testing database authority from live catalogs.
Verified facts about the Cloudflare account that hosts Justin's personal
M365 Assessor / CIS: findings, remediation briefs, gate results, owner rulings.
Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.
Use when proving credential-free reviewer isolation.
Use when integrating secure high-level process launchers.
Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services. Use when auditing dependencies for known vulnerabilities, triaging package-manager audit findings, or assessing supply-chain risk in a new package. Use when personal data or privacy compliance (GDPR, CCPA) is involved.
Research report for owner decision: one self-hosted, open-source OpenID Connect
Research report for owner decision: which self-hosted, open-source secrets
Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
How to ship a change to Justin's personal workbench: the static site in the
Use this runbook when a workbench section is reachable without a login,