- Web Security Headers — Bảo Vệ Website Từ HTTP Headers
Các HTTP security headers quan trọng: CSP, HSTS, X-Frame-Options, Permissions-Policy — cấu hình và best practices.
4 minVietnamese - Why and How to Turn Off Cloudflare Email Address Obfuscation
Understand why Cloudflare Email Address Obfuscation breaks JS apps and layouts, and how to disable it via dashboard.
2 minEnglish - Authentication — SSO, LDAP, WebAuthn, Passkeys
Các phương thức xác thực hiện đại: Single Sign-On, LDAP, WebAuthn, Passkeys — so sánh và triển khai.
4 minVietnamese - Rate Limiting — Thuật Toán Và Implementation Cho API
Các thuật toán rate limiting: Token Bucket, Leaky Bucket, Sliding Window — implementation trong Node.js và Cloudflare Workers.
5 minVietnamese - API Security — OAuth2, JWT Và Bảo Vệ Endpoint
Cơ chế xác thực và phân quyền cho API: OAuth2 flow, JWT best practices, và các biện pháp bảo vệ endpoint.
5 minVietnamese - Deno — JavaScript Runtime An Toàn TypeScript Native
Deno là runtime JavaScript/TypeScript an toàn mặc định, không npm, TypeScript native. Runtime đơn nhị phân, Web API tương thích, permissions.
6 minVietnamese - JSON Web Token (JWT) — Từ Cấu Trúc Đến Implementation
JWT deep dive: cấu trúc token, signing algorithms, refresh token rotation, blacklist, và security best practices.
5 minVietnamese - Strix — AI Hacker Mã Nguồn Mở Tự Động Tìm Lỗ Hổng Bảo Mật
Strix là AI Security Agent mã nguồn mở — tự động phân tích ứng dụng, tìm lỗ hổng, khai thác thử, tạo PoC và báo cáo. Pentest tự động bằng AI.
3 minVietnamese
Back