Security demos
Each demo takes
?mode=unsafe
or
?mode=safe
. Run both and compare.
input validation
zod at the edge
SQL injection
bound parameters
XSS
output escaping
CSRF
signed double-submit token
secrets hygiene
what an endpoint may say about config
rate limiting
D1-backed fixed window, 3 per 10s
boom
a deliberate crash, for reading stack traces