Profile    Mohammed Shiroz Status   Loading  
Logo
Share This

My security
blog and Updates

It's my personal blog and my post about what was my interested in. Not regularly. If you have any questions any discussion, I'm happy you get in touch with me, and try to answer as many as possible!

Blog
Let's See
Back to blog
Filter by:
Tags
//Article

Laravel Validation Rules You're Probably Not Using (But Should Be)

Laravel Validation Rules You're Probably Not Using (But Should Be)

Blog Summary

Most Laravel apps validate with required, string and max, then hand-code the rest in controllers. Unique-ignore, scoped exists, sometimes, bail, prohibited_if, Password and enum rules do it better. Each one with the problem it solves.

Read more
  • 113
  • 141
  • 3

SSH Keys Explained: How They Work and How to Use Them Safely

SSH Keys Explained: How They Work and How to Use Them Safely

Blog Summary

Bots try passwords on every server, all day. SSH keys make that pointless. Here's how key pairs work, a step-by-step ed25519 setup, the sshd_config gotcha that keeps passwords on, and habits that keep keys safe.

Read more
  • 106
  • 149
  • 23

Mass Assignment in Laravel: The Bug Hiding in Your create() Call

Mass Assignment in Laravel: The Bug Hiding in Your create() Call

Blog Summary

One extra field in a registration request, is_admin=1, and a stranger is an administrator. How mass assignment works in Laravel, why $guarded = [] plus $request->all() is a trap, and the habits that close the hole.

Read more
  • 120
  • 130
  • 3

Me vs CORS: A Love Story in Five Bad Ideas and One Good One

Me vs CORS: A Love Story in Five Bad Ideas and One Good One

Blog Summary

Every developer's relationship with CORS goes through the same stages: denial, wildcards, browser flags and bargaining. Here are the bad ideas we all try, why they fail, and the boring fix that actually works.

Read more
  • 110
  • 120
  • 8

Environment Variables and Secrets: Keeping API Keys Out of Your Code (and Git History)

Environment Variables and Secrets: Keeping API Keys Out of Your Code (and Git History)

Blog Summary

Deleting a leaked key from your code doesn't un-leak it. How .env files really work, why Laravel's config cache changes the rules, when to reach for a secret manager, and what to do in the first hour after a leak.

Read more
  • 87
  • 42
  • 21

Hashing vs Encryption vs Encoding: The One Question That Tells Them Apart

Hashing vs Encryption vs Encoding: The One Question That Tells Them Apart

Blog Summary

"The passwords are encrypted, we base64 them" contains two mistakes. Hashing, encryption and encoding solve different problems. One question tells them apart, plus why SHA-256 is wrong for passwords and bcrypt or Argon2id is right.

Read more
  • 124
  • 34
  • 24

01. About Shiroz

Mohammed Shiroz

Hi, I'm Mohammed Shiroz, a software engineer and AI enthusiast from Sri Lanka who turns ideas into intelligent, real-world solutions. With over 9 years of hands-on experience, I currently lead real estate ERP development at Kate Group, a...

03.My Projects

04. Categories

Ready To Start Your Project ?

Get in Touch
Close