Blog
Thoughts on development, design, and everything in between.
8/1/2026
One Finding, Maximum Impact: A Permissive Cross-Origin Policy
A civic content platform on a modern stack produced a single finding of the highest severity. It needed no version check and no exploit; the browser already did the work.
corsaccess-controlpublic-datasingle-finding
6/6/2026A Row Level Security Policy Is A Boundary You Have To Test From The Client Side
A platform-generated application stored every tenant table behind row level security. The policy was correct on paper and bypassable in practice, because the client held a key the policy trusted too much.
rlsauthorizationaccess-controlmulti-tenant