安全加固
原名:security-and-hardening
强化代码安全性,防范漏洞。处理用户输入、认证、数据存储或外部集成时使用。适用于任何接受不可信数据、管理用户会话或对接第三方服务的功能。
- 分类
- 开发提效
- 版本
- v1.0.0
- 作者
- 胡轩(@userdittm6)
- 下载
- 2
- 收藏
- 0
- 发布
- 2026-08-08
- 更新
- 2026-08-14
- TRACE 评分
- 4.2 / 5
内容概览
Security-first development practices for web applications. Treat every external input as hostile, every secret as sacred, and every authorization check as mandatory. Security isn't a phase — it's a constraint on every line of code that touches user data, authentication, or external systems. - Building anything that accepts user input - Implementing authentication or authorization - Storing or transmitting sensitive data - Integrating with external APIs or services - Adding file uploads, webhooks, or callbacks - Handling payment or PII data Controls bolted on without a threat model are guesses. Before hardening, spend five minutes thinking like an attacker: 1. Map the trust boundaries. Where does untrusted data cross into your system? HTTP requests, form fields, file uploads, webhooks, third-party APIs, message queues, and LLM output . Every boundary is attack surface. 2. Name the assets.…