Protecting what you build.
VALIDATE EVERY INPUT
At the server, regardless of browser checks.
PARAMETERISE EVERY QUERY
Without exception.
ESCAPE EVERYTHING DISPLAYED
So content cannot be interpreted as markup.
PROTECT AGAINST CROSS-SITE SUBMISSIONS
Enable your framework's protection.
SECURE SESSIONS AND COOKIES
Secure flag, inaccessible to scripts, sensible expiry.
STORE PASSWORDS CORRECTLY
An established password hashing function. Never your own.
ENFORCE AUTHORISATION SERVER-SIDE
On every protected route. Hiding a link is not access control.
DO NOT EXPOSE ERRORS
Tracebacks in production reveal paths, versions and sometimes credentials.
Return a generic message and log the detail.
KEEP DEPENDENCIES UPDATED
Framework vulnerabilities are published and scanned for.
DO NOT RUN IN DEBUG MODE IN PRODUCTION
That single setting has exposed a great many applications.
RATE LIMIT
Login, registration, and anything expensive.
WHAT TO REVIEW
All of the above, before any application goes live.