▸case-04 Our Single Page Application receives an authentication JWT from the auth server after login. The frontend team suggests storing the JWT in browser localStorage so it persists across sessions easily. Provide the recommended security pattern for storing and transmitting this session token on the web client. | pass→pass | 16,422 | 15,285 | -7% | 1 | 1 | 0% | 2,631 | 2,578 | -2% | 0 | 0 | — |
▸case-01 We are updating our Python user registration microservice. The current code uses SHA-256 with a static salt for password storage because developers thought SHA-256 was fast and secure. Provide the updated Python code snippet for hashing user passwords securely during sign-up. | pass→pass | 10,794 | 10,640 | -1% | 1 | 1 | 0% | 1,943 | 2,253 | +16% | 0 | 0 | — |
▸case-02 Our Node.js Express backend queries a PostgreSQL database. The developer wrote `db.query('SELECT * FROM users WHERE email = \'' + req.body.email + '\' AND password = \'' + req.body.password + '\'')`. Refactor this code to execute the query safely against SQL injection vulnerabilities. | pass→pass | 8,361 | 34,194 | +309% | 1 | 1 | 0% | 1,755 | 2,135 | +22% | 0 | 0 | — |
▸case-03 A frontend JavaScript function renders user comment text into a div element using `element.innerHTML = comment.text`. Users are attempting to inject malicious script tags. Refactor this JavaScript function to prevent DOM-based XSS while rendering user text safely. | pass→pass | 7,912 | 7,715 | -2% | 1 | 1 | 0% | 1,348 | 1,734 | +29% | 0 | 0 | — |
▸case-05 In an Express.js API, the developer configured cross-origin requests using `app.use(cors({ origin: '*', credentials: true }))` to fix frontend CORS errors when sending cookies. Browsers reject this configuration. Show the corrected CORS configuration for a trusted domain `https://app.example.com`. | pass→pass | 5,114 | 5,899 | +15% | 1 | 1 | 0% | 974 | 1,267 | +30% | 0 | 0 | — |
▸case-06 Our security auditor flagged our Content Security Policy header `Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'`. Explain the risk of `unsafe-eval` and show the revised CSP header directive for script sources. | pass→pass | 12,024 | 11,140 | -7% | 1 | 1 | 0% | 1,935 | 1,875 | -3% | 0 | 0 | — |
▸case-07 An internal banking portal uses traditional cookie-based authentication. External websites can submit POST forms directly to `/transfer` and the browser automatically sends the user's session cookie. How should cookie attributes and backend requests be configured to prevent CSRF attacks? | pass→pass | 10,235 | 9,482 | -7% | 1 | 1 | 0% | 2,360 | 1,949 | -17% | 0 | 0 | — |
▸case-08 A Node.js file download endpoint receives a filename query parameter: `const filePath = path.join('/var/www/uploads', req.query.filename); res.sendFile(filePath);`. Attackers pass `../../etc/passwd`. Refactor this code to safely prevent path traversal attacks. | pass→pass | 11,550 | 9,934 | -14% | 1 | 1 | 0% | 2,307 | 2,246 | -3% | 0 | 0 | — |
▸case-09 In our JWT verification code using `jsonwebtoken` in Node.js, the developer wrote `jwt.verify(token, secret, { algorithms: ['HS256', 'none'] })` to handle unsigned tokens in test environments. What vulnerability does this introduce and how should the algorithm configuration be corrected for production? | fail→pass | 8,752 | 9,392 | +7% | 1 | 1 | 0% | 1,566 | 1,784 | +14% | 0 | 0 | — |
▸case-10 Our login endpoint `/api/v1/login` is vulnerable to credential stuffing attacks because there are no request limits. Write an Express.js middleware snippet configured appropriately to protect this authentication route. | pass→pass | 8,944 | 11,697 | +31% | 1 | 1 | 0% | 1,806 | 2,039 | +13% | 0 | 0 | — |
▸case-11 A backend service logs incoming HTTP requests using `console.log('Request body:', req.body)` for debugging. Incoming payloads contain `username`, `password`, and `credit_card`. What security logging practice must be applied to this handler? | pass→pass | 9,282 | 7,861 | -15% | 1 | 1 | 0% | 1,701 | 1,548 | -9% | 0 | 0 | — |
▸case-12 A webhook integration feature allows users to submit a callback URL, which our server fetches using `fetch(userProvidedUrl)`. Attackers submit internal metadata URLs like `http://169.254.169.254/latest/meta-data/`. How should input validation and outbound requests be handled to mitigate SSRF? | pass→pass | 18,173 | 17,387 | -4% | 1 | 1 | 0% | 3,097 | 3,564 | +15% | 0 | 0 | — |
▸case-13 A legacy Java endpoint parses incoming user-uploaded XML files using `DocumentBuilderFactory.newInstance()`. Security scanning flagged potential XML External Entity (XXE) attacks. Provide the configuration lines needed on `DocumentBuilderFactory` to disable external DTDs. | pass→pass | 5,756 | 6,971 | +21% | 1 | 1 | 0% | 1,109 | 1,599 | +44% | 0 | 0 | — |
▸case-14 A Node.js application sets a session cookie with `res.cookie('session_id', token)`. What cookie attributes must be set to protect the session identifier from client-side script access and network sniffing over unencrypted connections? | pass→pass | 5,168 | 4,562 | -12% | 1 | 1 | 0% | 919 | 991 | +8% | 0 | 0 | — |
▸case-15 A user profile update route allows image uploads (`.jpg`, `.png`). The current code checks file extension using `file.originalname.endsWith('.jpg')` before saving to a public folder. Explain why this is vulnerable and provide secure file upload handling steps. | pass→pass | 16,258 | 14,590 | -10% | 1 | 1 | 0% | 3,027 | 3,002 | -1% | 0 | 0 | — |
▸case-16 In an Express/Mongoose app, the endpoint user update handler is written as `User.findByIdAndUpdate(req.params.id, req.body)`. Attackers send `{ "isAdmin": true }` in the request body to escalate privileges. How should this route handler be rewritten to prevent mass assignment? | pass→pass | 10,091 | 10,203 | +1% | 1 | 1 | 0% | 2,110 | 1,997 | -5% | 0 | 0 | — |
▸case-17 After login, a web application redirects users using `res.redirect(req.query.next)`. Attackers supply `next=https://attacker.com/phishing`. How should the redirect URL be validated before executing the HTTP redirect? | pass→pass | 13,562 | 9,941 | -27% | 1 | 1 | 0% | 2,510 | 2,061 | -18% | 0 | 0 | — |
▸case-18 An Express.js REST API is missing fundamental security headers like X-Content-Type-Options, Strict-Transport-Security, and X-Frame-Options. Show how to integrate standard middleware in Express.js to automatically attach these HTTP response headers. | pass→pass | 9,526 | 8,560 | -10% | 1 | 1 | 0% | 1,786 | 1,741 | -3% | 0 | 0 | — |
▸case-19 A backend service generates password reset tokens using `Math.random().toString(36).substring(2)`. Explain why this is insecure and provide the Node.js code snippet using the built-in `crypto` module to generate a cryptographically secure random token. | pass→pass | 11,279 | 9,796 | -13% | 1 | 1 | 0% | 1,830 | 1,783 | -3% | 0 | 0 | — |
▸case-20 We are configuring AWS Security Groups for a multi-tier VPC architecture containing web servers in public subnets and PostgreSQL database instances in private subnets. Provide the inbound port and network security rules for the database security group. | pass→pass | 9,803 | 11,851 | +21% | 1 | 1 | 0% | 1,752 | 2,046 | +17% | 0 | 0 | — |
▸case-21 Our CI/CD pipeline runs Trivy image scans on Docker containers and flagged CVEs in Debian base OS packages `apt`, `libssl1.1`, and `glibc`. How should we update the Dockerfile base image layer to remediate OS-level package vulnerabilities? | pass→pass | 12,558 | 12,177 | -3% | 1 | 1 | 0% | 2,275 | 2,373 | +4% | 0 | 0 | — |
▸case-22 Our compliance team needs a policy document specifying physical entry controls, badge logging, and environmental monitoring for server rooms in physical datacenters. Outline the key requirements for physical facility access control. | pass→pass | 21,458 | 13,270 | -38% | 1 | 1 | 0% | 3,266 | 2,549 | -22% | 0 | 0 | — |