Skip to main content

10 docs tagged with "security"

View all tags

ACLs and Permissions

AEM's permission model is built on Jackrabbit Oak's access control layer. Every read,

Agent Security & Sandboxing

How to secure tool-using LLM agents with threat modeling, prompt-injection defenses, sandboxing, egress controls, least-privilege tools, approval gates, and audit trails.

AI Safety & Guardrails

What guardrails are and how they work, their documented limitations, the attack surface (prompt injection and jailbreaking), red-teaming as an evaluation method, and the layered, defense-in-depth approach to deploying LLMs responsibly.

API Security Hardening

Strapi API security hardening: strict parameter validation, controller sanitization, ownership checks, token types, rate limiting, CORS, CSP, and production checklist.

Authentication and Permissions

Strapi authentication and permissions: JWT flow, user registration, role-based access control, custom providers, API tokens, and permission hardening.

MCP & A2A in Production

Production notes for Model Context Protocol and Agent2Agent - architecture, transports, authorization, security, registries, observability, and adoption trade-offs.

Middleware and Policies

Strapi middleware and policies: request/response manipulation, access control, rate limiting, logging, is-owner patterns, and global vs route-level middleware.

Security Basics

Security in AEM is a multi-layered concern that spans user management, access control, request filtering,

Service Users and Repoinit

End-to-end guide to AEM service users - creating them with repoinit, mapping them to bundles, obtaining service resource resolvers, and debugging permission problems on AEM 6.5 and AEM as a Cloud Service.