Security
Input validation
Validation constrains data shape, ranges, and allowed values.
REFERENCE CATEGORY
19 practical topics
Security
Validation constrains data shape, ranges, and allowed values.
Security
Injection happens when input changes SQL structure instead of remaining data.
Security
XSS lets attacker-controlled text execute as script in a browser.
Security
CSRF exploits browser credentials on unwanted cross-site mutations.
Security
Authentication identifies the actor; authorization determines permitted actions.
Security
Secure authentication verifies credentials and manages sessions safely.
Security
RBAC assigns capabilities via roles, combined with resource scope.
Security
Password hashes allow verification without storing plaintext.
Security
Sessions associate a browser with authenticated server-side state.
Security
Rate limits bound abusive request frequency.
Security
Mass assignment writes many model attributes from an array.
Security
Response headers can reduce browser-side exposure.
Security
Secrets include credentials, tokens, and encryption keys.
Security
Security logs record relevant events without unnecessary sensitive data.
Security
Audit records document who did what, when, and to which entity.
Security
Least privilege grants only the access necessary for a task.
Security
Safe errors reveal useful client information without internal details.
Security
Uploads introduce untrusted bytes, names, and storage paths.
Security
ISO/IEC 27001 concerns an organizational information security management system.