Four small, independent checks — a threat model, a URL allowlist, a token verifier, a secrets scanner — that between them cover every trap this phase warned about. Each one has an obviously wrong shortcut that looks correct until you feed it the input the shortcut was built to dodge.
A small service needs four pieces of security tooling before it ships. None of them are hard algorithms — every one of them is a place where the easy implementation is also the wrong one, and it keeps working right up until someone deliberately targets the gap:
classify_stride — given one data-flow edge as a dict of booleans, return the
STRIDE letters that apply. A flow that never crosses a trust boundary has no STRIDE
exposure at all — reporting one anyway is noise nobody will read twice.is_safe_url — an SSRF allowlist check. The obvious version does a substring
match against the allowlist, which a URL can defeat just by mentioning the trusted host
somewhere it isn't the host.verify_jwt — checks a token's alg before trusting anything, then
verifies the HMAC signature. Skip the alg check and alg: none walks
straight through.find_hardcoded_secrets — flags a line only when it assigns a real literal to a
secret-shaped name. A scanner that fires on the word "secret" anywhere lights up on every
comment, every os.environ.get("API_KEY") and every placeholder — and gets
switched off by the next engineer within a week."trusted.com" in url is true for
http://evil.com/?u=trusted.com and for http://trusted.com@evil.com/ —
the substring is present, the host is not. The checks build both, plus a scheme trick
(file://), so a host-only comparison on the parsed URL is the only thing that
survives.
alg, never checking the signature — still "works" on every token you hand it
honestly. It only fails the moment someone hands it {"alg":"none"} or a payload
edited after the signature was computed. Both are in the checks.
The grader runs your code, then runs 4 checks against it with data you can't see — so solving the example instead of the problem will fail. Each check reports exactly what it expected and what it got. All 4 green marks this phase ready ✓ on your roadmap.
That you reach for the parsed, structural check instead of the string-matching one that happens to work on today's inputs. A substring allowlist, a JWT verifier that trusts the header, and a secrets grep that fires on the word "secret" all pass code review because they look like the real thing — they just don't survive an adversary who read the same source you did.