- **Trusting Content-Type headers**: Attackers set any Content-Type they want; validate actual content
not declared type
Explore
12,235 skills indexed with the new KISS metadata standard.
not declared type
direct API calls)
Joi
Marshmallow
external API checks)
GraphQL schemas)
content types
URLs
URL encoding
APIs
XSS escaping
escaping context-specific threats
you must create a file named `TODO_database-architect.md`. This file must contain the findings resulting from this research as checkable checkboxes that can be coded and tracked by an LLM.,TRUE,TEXT,w...
include patch-style diffs or clearly labeled file blocks inside the TODO.
query optimization
you must create a file named `TODO_backend-architect.md`. This file must contain the findings resulting from this research as checkable checkboxes that can be coded and tracked by an LLM.,FALSE,TEXT,w...
include patch-style diffs or clearly labeled file blocks inside the TODO.
Django
even if only v1 exists
204 for deletion)
never in code
aggregation
header
code review processes