TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Security Checklist for Full Stack Web Developers

65 pointsby benthehentenover 7 years ago

3 comments

cl0rksterover 7 years ago
I&#x27;m not sure that logrocket belongs on such a &quot;security&quot; checklist. While I understand the value that they propose to offer, I&#x27;m not sure that wholesale recording your users&#x27; sessions and then sending them to a third-party server for storage and retrieval really meshes with my idea of security - especially if the site contains PII. I fully understand that you can intentionally do work to hide that information from logrocket, but that is putting a lot of trust in both devs and in logrocket to get that one right.<p>While there may be such a tool, I&#x27;m not aware of something like this that runs as a first party script and uses local storage. It would indeed be very useful to escape the logs-&gt;screenshots-&gt;can&#x27;t reproduce cycle mentioned.
评论 #15126697 未加载
flavio81over 7 years ago
TL;DR: The advice is:<p><i>&quot;use Open source software&quot;, &quot;add logging&quot;, &quot;set all pages to HTTPS&quot;</i> and follow a <i>&quot;top 10 list of the most critical security threats&quot;</i><p>Sad state of things.<p>The concept of having your work done by &quot;Full Stack Developer&quot; will not be nice for opening up potential security holes, in my opinion.<p>Additionally, I don&#x27;t think there exists a real &quot;Full Stack&quot; dev, and I&#x27;m not alone in this opinion; click anywhere:<p><a href="https:&#x2F;&#x2F;medium.com&#x2F;swlh&#x2F;the-full-stack-developer-is-a-myth-4e3fb9c25867" rel="nofollow">https:&#x2F;&#x2F;medium.com&#x2F;swlh&#x2F;the-full-stack-developer-is-a-myth-4...</a><p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=10182936" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=10182936</a><p><a href="http:&#x2F;&#x2F;andyshora.com&#x2F;full-stack-developers.html" rel="nofollow">http:&#x2F;&#x2F;andyshora.com&#x2F;full-stack-developers.html</a><p><a href="https:&#x2F;&#x2F;frontendmasters.com&#x2F;books&#x2F;front-end-handbook&#x2F;2017&#x2F;practice&#x2F;myth.html" rel="nofollow">https:&#x2F;&#x2F;frontendmasters.com&#x2F;books&#x2F;front-end-handbook&#x2F;2017&#x2F;pr...</a><p><a href="https:&#x2F;&#x2F;vitamintalent.com&#x2F;blog&#x2F;the-myth-of-the-full-stack-developer" rel="nofollow">https:&#x2F;&#x2F;vitamintalent.com&#x2F;blog&#x2F;the-myth-of-the-full-stack-de...</a><p><a href="https:&#x2F;&#x2F;techcrunch.com&#x2F;2014&#x2F;11&#x2F;08&#x2F;the-rise-and-fall-of-the-full-stack-developer&#x2F;" rel="nofollow">https:&#x2F;&#x2F;techcrunch.com&#x2F;2014&#x2F;11&#x2F;08&#x2F;the-rise-and-fall-of-the-f...</a><p><a href="https:&#x2F;&#x2F;www.propelrr.com&#x2F;blog&#x2F;ux&#x2F;full-stack-web-developer.html" rel="nofollow">https:&#x2F;&#x2F;www.propelrr.com&#x2F;blog&#x2F;ux&#x2F;full-stack-web-developer.ht...</a>
评论 #15128319 未加载
评论 #15126926 未加载
gandreaniover 7 years ago
&gt; In Node, if you use Express (find out in the next article why you shouldn’t , but most people do)<p>Now that&#x27;s just mean. Why can&#x27;t he just say it there!
评论 #15126571 未加载
评论 #15126653 未加载
评论 #15126658 未加载