Profile    Mohammed Shiroz Status   Loading  
Logo
Share This

My security
blog and Updates

It's my personal blog and my post about what was my interested in. Not regularly. If you have any questions any discussion, I'm happy you get in touch with me, and try to answer as many as possible!

Blog
Let's See
Back to blog
Filter by:
Tags
//Article

Writing Webhooks You Can Trust: A Laravel Guide to Receiving Them Safely

Writing Webhooks You Can Trust: A Laravel Guide to Receiving Them Safely

Blog Summary

A webhook endpoint is a public URL that changes your data, so anyone who finds it can try. Here's how to receive webhooks safely in Laravel 12: verify signatures, block replays, store first, process on a queue, and handle duplicates.

Read more
  • 18
  • 102
  • 5

How "Sign in With Google" Works Behind the Button (and the Checks You Shouldn't Skip)

How "Sign in With Google" Works Behind the Button (and the Checks You Shouldn't Skip)

Blog Summary

One click, pick an account, you're in. Behind it: OpenID Connect, a signed ID token and a few checks that decide whether the right person gets the right account. Here's the full flow, the token, and a Laravel Socialite setup.

Read more
  • 67
  • 124
  • 4

How I Review AI-Generated Pull Requests: My Six-Step Checklist

19 Aug 2026Category : Blog
How I Review AI-Generated Pull Requests: My Six-Step Checklist

Blog Summary

AI-generated code is hard to review because it always looks right. Here's the routine I follow for PRs that started in an agent session: intent first, tests before code, a separate security pass, and actually running it.

Read more
  • 143
  • 47
  • 9

Zero Trust Security Explained Simply: Why "Inside the Network" Means Nothing

Zero Trust Security Explained Simply: Why "Inside the Network" Means Nothing

Blog Summary

Once you got past reception, the old office let you wander anywhere. Networks worked the same way, and attackers love it. Here's zero trust in plain words: identity, least privilege, device checks, and where to start.

Read more
  • 108
  • 133
  • 3

JWT vs Sessions vs API Keys: Which One to Use, and When

JWT vs Sessions vs API Keys: Which One to Use, and When

Blog Summary

"We use JWT" is often the answer for the web app, the mobile app and the partner integration alike. Sessions, JWTs and API keys solve different problems; here's how to tell which one each caller needs.

Read more
  • 96
  • 91
  • 22

The Security Headers Most Sites Forget (and How to Add Them in Laravel)

The Security Headers Most Sites Forget (and How to Add Them in Laravel)

Blog Summary

A few lines of HTTP headers can stop clickjacking, script injection and leaky URLs, and most sites still skip them. The common mistakes with CSP, HSTS, frame-ancestors, Referrer-Policy and Permissions-Policy, plus a Laravel middleware.

Read more
  • 128
  • 23
  • 3

01. About Shiroz

Mohammed Shiroz

Hi, I'm Mohammed Shiroz, a software engineer and AI enthusiast from Sri Lanka who turns ideas into intelligent, real-world solutions. With over 9 years of hands-on experience, I currently lead real estate ERP development at Kate Group, a...

03.My Projects

04. Categories

Ready To Start Your Project ?

Get in Touch
Close