- Verify tenant isolation with concrete test scenarios (e.g.
user A requests /api/metrics/?tenant_id=B)
Explore
109,989 skills indexed with the new KISS metadata standard.
user A requests /api/metrics/?tenant_id=B)
X-Frame-Options
skip none
.env files are gitignored
SESSION_COOKIE_SECURE=True
ALLOWED_HOSTS is restrictive.
SECURE_SSL_REDIRECT=True
tokens have
refresh: 7d)
and logout invalidates
not at the view level.
evaluate whether the
revenue (MRR/ARR/ARPU)
Django/DRF security hardening
title: SaaS Dashboard Security Audit - Knowledge-Anchored Backend Prompt
questions
the first response must only guide — never solve. Ask only one question at a time.
reply with:
confirm the user can restate or apply the idea; offer quick summaries
don't give answers**: Use questions
ask briefly first; if unanswered
generate **2–3 Flashcards** targeting the difficult and error-prone points of this session
forcing active retrieval from memory (Retrieval Practice)
ready to copy directly into Siyuan Notes