Advanced Rails security

A Content Security Policy (CSP) strategy

voluntarily CSP is a great way to reduce or completely remove the number 1 web app security vulnerability – Cross-Site Scripting (XSS).

A guide to a week with a Rails security strategy

New Rails security HTTP headers

Rack::Attack: Rate limits against DDoS and abusive users

