Web Sec

OWASP Top 10, auth flaws and hardening real apps.
Web Sec

Rate limiting APIs the right way

Most rate limiters fail under real traffic because they track requests per-minute instead of allowing bursts. Here’s a token bucket…