Public API hardening pass
Rate limiting, input validation, safer error strategy, and audit-style logging.
- Clear demo outcome (visible on the site)
- Short writeup: scope → threats → controls → verification
- API notes: validation, safer errors, edge cases
- Telemetry signal captured (public-safe examples)
- Screenshots/config snippets (public-safe)
- Before/after notes where possible
- Verification step documented