Profile    Mohammed Shiroz Status   Loading  
Logo
Share This

My web security
blog and Updates

It's my personal blog and my post about what was my interested in. Not regularly. If you have any questions any discussion, I'm happy you get in touch with me, and try to answer as many as possible!

Blog
Let's See
Back to blog
Filter by:
Tags
//Article

The Security Headers Most Sites Forget (and How to Add Them in Laravel)

The Security Headers Most Sites Forget (and How to Add Them in Laravel)

Blog Summary

A few lines of HTTP headers can stop clickjacking, script injection and leaky URLs, and most sites still skip them. The common mistakes with CSP, HSTS, frame-ancestors, Referrer-Policy and Permissions-Policy, plus a Laravel middleware.

Read more
  • 112
  • 146
  • 18

Sessions Explained: How Websites Remember Who You Are

Sessions Explained: How Websites Remember Who You Are

Blog Summary

HTTP forgets you after every request, yet you stay logged in for hours. Here's what really happens: the session ID cookie, server-side storage, expiry, session fixation, and choosing a Laravel session driver.

Read more
  • 21
  • 16
  • 6

File Upload Security Mistakes in PHP Apps (and the Safe Laravel Way)

File Upload Security Mistakes in PHP Apps (and the Safe Laravel Way)

Blog Summary

An upload form lets a stranger put a file on your server. Five classic PHP upload mistakes, from trusting the MIME type to storing files in the web root, why each one is dangerous, and the safe Laravel approach.

Read more
  • 121
  • 90
  • 7

Me vs CORS: A Love Story in Five Bad Ideas and One Good One

Me vs CORS: A Love Story in Five Bad Ideas and One Good One

Blog Summary

Every developer's relationship with CORS goes through the same stages: denial, wildcards, browser flags and bargaining. Here are the bad ideas we all try, why they fail, and the boring fix that actually works.

Read more
  • 112
  • 148
  • 8

OAuth 2.0 Explained Without the Jargon: The Valet Key Guide

OAuth 2.0 Explained Without the Jargon: The Valet Key Guide

Blog Summary

OAuth is a valet key for your data: it lets an app park the car without reading your mail. The authorization code flow with PKCE explained step by step, plus scopes, tokens and OAuth vs OpenID Connect.

Read more
  • 124
  • 12
  • 12

Securing a Laravel App: A Practical 12-Point Checklist Before You Go Live

Securing a Laravel App: A Practical 12-Point Checklist Before You Go Live

Blog Summary

Laravel ships with strong security defaults, so apps get breached in boring ways: a debug flag, a mass-assignment slip, a missing ownership check. Here is the 12-point checklist I run before going live.

Read more
  • 59
  • 137
  • 18

01. About Shiroz

Mohammed Shiroz

Hi, I'm Mohammed Shiroz, a software engineer and AI enthusiast from Sri Lanka who turns ideas into intelligent, real-world solutions. With over 9 years of hands-on experience, I currently lead real estate ERP development at Kate Group, a...

03.My Projects

04. Categories

Ready To Start Your Project ?

Get in Touch
Close