Object-level authorization gaps we still find in 2026
Partner tokens, nested resources, and the checklist item everyone marks done too early.
Field notes
Practical notes from secure code review and hardening work — decisions, patterns, and mistakes we see on real codebases.
Short articles rooted in the work we do with engineering teams. No generic productivity advice — only topics that show up in reviews.
Partner tokens, nested resources, and the checklist item everyone marks done too early.
Same site, different clients — why cookie flags that look correct still fail a hardening review.
How to choose launch-critical paths so a short assessment still changes the go/no-go call.
A half-day map of trust boundaries beats weeks of rewriting role checks after go-live.