Profile    Mohammed Shiroz Status   Loading  
Logo
Share This

My security
blog and Updates

It's my personal blog and my post about what was my interested in. Not regularly. If you have any questions any discussion, I'm happy you get in touch with me, and try to answer as many as possible!

Blog
Let's See
Back to blog
Filter by:
Tags
//Article

Securing a Laravel App: A Practical 12-Point Checklist Before You Go Live

Securing a Laravel App: A Practical 12-Point Checklist Before You Go Live

Blog Summary

Laravel ships with strong security defaults, so apps get breached in boring ways: a debug flag, a mass-assignment slip, a missing ownership check. Here is the 12-point checklist I run before going live.

Read more
  • 140
  • 125
  • 25

CORS Explained: Why the Browser Blocks Your API Call (and Postman Doesn't)

CORS Explained: Why the Browser Blocks Your API Call (and Postman Doesn't)

Blog Summary

The request works in Postman, works with curl, and fails in the browser with a scary red error. CORS isn't your server refusing the call. Here's what the browser is really doing, and how to fix it properly in Laravel.

Read more
  • 55
  • 19
  • 5

Rate Limiting Your API: The Algorithms and a Laravel Example

Rate Limiting Your API: The Algorithms and a Laravel Example

Blog Summary

One script hammering your login endpoint can slow the app for everyone. Here's how fixed window, sliding window and token bucket limiting really differ, and how to set up sensible per-user limits in Laravel.

Read more
  • 150
  • 50
  • 20

JWT Explained: What's Inside the Token and What Can Go Wrong

JWT Explained: What's Inside the Token and What Can Go Wrong

Blog Summary

Paste any JWT into a decoder and you can read it, no key needed. That surprises a lot of developers. Here's what's really inside a token, why base64 isn't encryption, and the mistakes that cause real breaches.

Read more
  • 26
  • 113
  • 22

Cookies vs Tokens: Where Should Your Web App Keep the Session?

Cookies vs Tokens: Where Should Your Web App Keep the Session?

Blog Summary

That login token in localStorage is readable by every script on your page. Here's the real trade-off between HttpOnly cookies and tokens, XSS vs CSRF, and how Laravel Sanctum handles SPAs and mobile apps.

Read more
  • 150
  • 103
  • 7

HTTPS in Plain English: Certificates, Keys and What the Padlock Really Means

HTTPS in Plain English: Certificates, Keys and What the Padlock Really Means

Blog Summary

The padlock doesn't mean a site is safe. Here's what HTTPS really does, in plain English: symmetric and asymmetric keys, the TLS handshake, what a certificate authority proves, and what HTTPS can't protect.

Read more
  • 45
  • 34
  • 16

01. About Shiroz

Mohammed Shiroz

Hi, I'm Mohammed Shiroz, a software engineer and AI enthusiast from Sri Lanka who turns ideas into intelligent, real-world solutions. With over 9 years of hands-on experience, I currently lead real estate ERP development at Kate Group, a...

03.My Projects

04. Categories

Ready To Start Your Project ?

Get in Touch
Close