Development
Development
- No secrets in code: Use environment variables
- Input validation: Validate all user inputs
- Output encoding: Encode all dynamic outputs
- Authentication: Use proven authentication libraries
- Authorization: Check permissions on every request
- Dependencies: Keep dependencies updated
- HTTPS: Always use HTTPS in production