API Security Best Practices
expeditedsecurity.com
expeditedsecurity.com
> Using Expedited WAF, the team temporarily blocked access to the site from China and was able to remain online to their business customers.
Most used feature of Expedited WAF.
>7) Cross Site Scripting (XSS). What is it: Manipulation of your API to further spread a malicious script. What you should do: Strongly filter all inputs for both corectness[sic] and script components.
I mean...yeah, but you should do this in all things...
> Using Expedited WAF, the team temporarily blocked access to the site from China and was able to remain online to their business customers.
Rest of it is generic API design advice