12 parts
Break a real app, then fix it: SQL injection, XSS, CSRF, broken access control, password storage, security headers, and supply-chain attacks.
A working threat model for web apps: who attacks them, what they're after, and the shape every lesson in this security series follows.
5 min read
Run a real SQL injection against a real in-browser SQLite database, watch every row come back, then fix it the way Linkstash actually does.
6 min read
How cross-site scripting turns a comment box into a way to run JavaScript on someone else's session, demonstrated live, then fixed with proper escaping.
How cross-site request forgery uses a browser's own cookie-sending rules to trigger actions a logged-in user never asked for, and how to actually stop it.
Credential stuffing, brute force, and the timing bug that leaks which emails have accounts, with the real fix from a login endpoint in production.
argon2id versus faster hashes, why a 12-character minimum beats complexity rules, and a real race condition in a signup endpoint under concurrent load.
Why returning 403 for someone else's resource is itself a leak, and why Linkstash returns 404 instead, with the real routes and requests to prove it.
What Content-Security-Policy, HSTS, and nosniff actually stop, why middleware order decides whether they apply at all, and where to add them in Express.
Why a leaked API key isn't fixed by deleting it from the latest commit, how .env files actually protect you, and what to do the moment a secret leaks.
Why a vulnerability in someone else's dependency is still your production incident, and the concrete habits (lockfiles, audits, pinning) that limit the blast radius.
A negative ?limit= that returns every row in a table, why SQLite treats it as no limit at all, and the real clamp that fixes it in Linkstash.
A full security review pass over Linkstash's real endpoints, tying every fix from this series (SQLi, XSS, IDOR, timing, rate limits) into one checklist.