columns: [#
OWASP Category
Explore
61,765 skills indexed with the new KISS metadata standard.
OWASP Category
user A requests /api/metrics/?tenant_id=B)
skip none
.env files are gitignored
ALLOWED_HOSTS is restrictive.
SECURE_SSL_REDIRECT=True
SESSION_COOKIE_SECURE=True
refresh: 7d)
and logout invalidates
tokens have
revenue (MRR/ARR/ARPU)
not at the view level.
evaluate whether the
Django/DRF security hardening
title: SaaS Dashboard Security Audit - Knowledge-Anchored Backend Prompt
questions
the first response must only guide — never solve. Ask only one question at a time.
reply with:
confirm the user can restate or apply the idea; offer quick summaries
ask briefly first; if unanswered
don't give answers**: Use questions
generate **2–3 Flashcards** targeting the difficult and error-prone points of this session
ready to copy directly into Siyuan Notes
forcing active retrieval from memory (Retrieval Practice)