Just noticed that I've been ignoring security for 3+ years. Somehow thought that Netlify defaults to some sort of BPs, but that was a very wrong assumption. -.-


It's better now: ttntm.me/notes#18

Next: github.com/ttntm/watch3r/issue which means also taking care of the http headers for the app's functions.

