ACLs and Permissions
AEM's permission model is built on Jackrabbit Oak's access control layer. Every read,
AEM's permission model is built on Jackrabbit Oak's access control layer. Every read,
How to secure tool-using LLM agents with threat modeling, prompt-injection defenses, sandboxing, egress controls, least-privilege tools, approval gates, and audit trails.
What guardrails are and how they work, their documented limitations, the attack surface (prompt injection and jailbreaking), red-teaming as an evaluation method, and the layered, defense-in-depth approach to deploying LLMs responsibly.
Strapi API security hardening: strict parameter validation, controller sanitization, ownership checks, token types, rate limiting, CORS, CSP, and production checklist.
Strapi authentication and permissions: JWT flow, user registration, role-based access control, custom providers, API tokens, and permission hardening.
Production notes for Model Context Protocol and Agent2Agent - architecture, transports, authorization, security, registries, observability, and adoption trade-offs.
Strapi middleware and policies: request/response manipulation, access control, rate limiting, logging, is-owner patterns, and global vs route-level middleware.
Security in AEM is a multi-layered concern that spans user management, access control, request filtering,
End-to-end guide to AEM service users - creating them with repoinit, mapping them to bundles, obtaining service resource resolvers, and debugging permission problems on AEM 6.5 and AEM as a Cloud Service.
Learn how to sanitize and validate user input in JavaScript with TypeScript examples. Covers frontend and backend basics, XSS prevention, and safe outputs.