security

ruby
class ApplicationPolicy
  attr_reader :user, :record

  def initialize(user, record)
    @user = user
    @record = record

Authorizing Controller Actions with Pundit Policy Objects in Rails

rails pundit authorization
by codesnips 3 tabs
python
import magic
from django import forms
from django.core.exceptions import ValidationError
from django.template.defaultfilters import filesizeformat

Validating Upload Size and MIME Type in a Custom Django Form Field

django forms file-upload
by codesnips 3 tabs
ruby
module ApplicationCable
  class Connection < ActionCable::Connection::Base
    identified_by :current_user

    def connect
      self.current_user = find_verified_user

ActionCable channel that streams Turbo updates safely

rails hotwire turbo
by codesnips 4 tabs
python
import threading
from contextlib import contextmanager

_state = threading.local()

Per-Tenant Data Isolation in Django with a Thread-Local Current Tenant Manager

django multi-tenancy orm
by codesnips 4 tabs
go
package session

import (
	"crypto/hmac"
	"crypto/sha256"
	"encoding/base64"

Stateless Session Cookies Signed and Verified With HMAC in Go

go security cookies
by codesnips 3 tabs
typescript
import { Exclude, Expose } from 'class-transformer';

export class User {
  id: string;

  firstName: string;

Hide Sensitive Fields in NestJS Responses with class-transformer and ClassSerializerInterceptor

nestjs class-transformer serialization
by codesnips 3 tabs
ruby
require "loofah"

class HtmlSanitizer
  ALLOWED_TAGS  = %w[p br a strong em ul ol li blockquote code pre h2 h3].freeze
  ALLOWED_ATTRS = %w[href title].freeze
  SAFE_SCHEMES  = %w[http https mailto].freeze

Safer HTML Sanitization Pipeline

rails security xss
by codesnips 4 tabs
go
package web

import (
  "bytes"
  "html/template"
  "net/http"

Template rendering with html/template and strict escaping

go templates http
by Leah Thompson 1 tab
java
public class PayloadLimitFilter extends OncePerRequestFilter {

    private final long maxBytes;
    private final Set<String> allowedTypes;

    public PayloadLimitFilter(long maxBytes, Set<String> allowedTypes) {

Enforce Request Payload Size and Content-Type with a Servlet Filter and Controller Guard

spring-boot servlet-filter validation
by codesnips 4 tabs
javascript
const jwt = require('jsonwebtoken');

const SECRET = process.env.JWT_SECRET;
const ALGORITHM = 'HS256';
const ACCESS_TTL = '15m';

JWT Authentication Middleware in Express That Populates req.user

express jwt authentication
by codesnips 3 tabs
javascript
const jwt = require('jsonwebtoken');

function authenticate(req, res, next) {
  const header = req.headers.authorization || '';
  const [scheme, token] = header.split(' ');

Role-Based Access Control in Express with a requireRole Middleware Factory

express middleware rbac
by codesnips 3 tabs
javascript
const { AsyncLocalStorage } = require('async_hooks');

const storage = new AsyncLocalStorage();

function runWithTenant(tenantId, userId, callback) {
  return storage.run({ tenantId, userId }, callback);

Per-Tenant Request Context in Express With AsyncLocalStorage and a Scoped Repository

express multi-tenancy middleware
by codesnips 4 tabs