c/security › command
0votes

Web app security reviewChecklist

submitted by u/client to c/security · 0 copies

Check an app against the issues attackers try first.

Checklist · 1 variable
Review {{app_or_code}} against this list. For each, answer PASS / FAIL / N/A with evidence:

1. Every API route checks authentication AND authorization (not just "logged in").
2. User input is validated server-side with an allowlist schema.
3. Queries are parameterized; no string-built SQL.
4. Output is escaped; no dangerouslySetInnerHTML with user data.
5. Secrets are server-only and never shipped to the browser bundle.
6. Cookies are HttpOnly, Secure, SameSite.
7. Rate limits on login, signup, password reset and write endpoints.
8. File uploads check type, size and are re-encoded or scanned.
9. Error messages don't leak stack traces or internal ids.
10. Dependencies have no known critical vulnerabilities.

Finish with the top 3 risks ranked by impact.
0 commentsreport
0 comments

Log in to join the discussion.