columns: [#
OWASP Category
Explore
110,113 skills indexed with the new KISS metadata standard.
OWASP Category
user A requests /api/metrics/?tenant_id=B)
skip none
.env files are gitignored
ALLOWED_HOSTS is restrictive.
SECURE_SSL_REDIRECT=True
SESSION_COOKIE_SECURE=True
refresh: 7d)
and logout invalidates
tokens have
revenue (MRR/ARR/ARPU)
not at the view level.
evaluate whether the
Django/DRF security hardening
title: SaaS Dashboard Security Audit - Knowledge-Anchored Backend Prompt
questions
the first response must only guide — never solve. Ask only one question at a time.
reply with:
ask briefly first; if unanswered
don't give answers**: Use questions
generate **2–3 Flashcards** targeting the difficult and error-prone points of this session
ready to copy directly into Siyuan Notes
forcing active retrieval from memory (Retrieval Practice)
please distill the key points above in your own words and send them to me for quality check.