Boss challenge: the security triage

Four small, independent checks — a threat model, a URL allowlist, a token verifier, a secrets scanner — that between them cover every trap this phase warned about. Each one has an obviously wrong shortcut that looks correct until you feed it the input the shortcut was built to dodge.

STRIDE SSRF JWT secrets no shortcuts

The situation

A small service needs four pieces of security tooling before it ships. None of them are hard algorithms — every one of them is a place where the easy implementation is also the wrong one, and it keeps working right up until someone deliberately targets the gap:

The SSRF trap: "trusted.com" in url is true for http://evil.com/?u=trusted.com and for http://trusted.com@evil.com/ — the substring is present, the host is not. The checks build both, plus a scheme trick (file://), so a host-only comparison on the parsed URL is the only thing that survives.
The JWT trap: a verifier that decodes the header and stops — never checking alg, never checking the signature — still "works" on every token you hand it honestly. It only fails the moment someone hands it {"alg":"none"} or a payload edited after the signature was computed. Both are in the checks.

Write it

The grader runs your code, then runs 4 checks against it with data you can't see — so solving the example instead of the problem will fail. Each check reports exactly what it expected and what it got. All 4 green marks this phase ready ✓ on your roadmap.

Phase 10 · boss challenge

Where is Python coming from? No server is involved. The browser downloads CPython compiled to WebAssembly the first time you press Run & grade, then runs your code locally. Nothing you write leaves the machine — which also means the grader is honest: it really executed what you wrote.

What passing actually proves

That you reach for the parsed, structural check instead of the string-matching one that happens to work on today's inputs. A substring allowlist, a JWT verifier that trusts the header, and a secrets grep that fires on the word "secret" all pass code review because they look like the real thing — they just don't survive an adversary who read the same source you did.

Take away: a security check that only has to survive honest input isn't a security check. Every function here has an easy version and a correct version, and the difference only shows up on the input built to find it.
Next: Back to the roadmap — see how far you've come