3 ms·
The API with a single call "createWithdrawl" is very good. Having code like this to begin with changes how all your future code works. It also is easier to deb
by steakejjs 12y ago
The API with a single call "createWithdrawl" is very good.
Having code like this to begin with changes how all your future code works. It also is easier to debug, simpler to explain, etc. You think twice about adding new API calls, which makes you think twice before you add new bugs. Having the ability to muck around with API calls you shouldn't be making will catch you eventually.
I've posted this before, but web-app security in most startups I look at is so bad. If it's written in PHP, I can normally find every bug in the book in under 5 minutes. What is worse on top of that is many companies don't respond (and don't fix) when you report bugs. I'm talking well known startups too.
I really think the OWASP Top 10 needs to be required reading for startup founders (or technical leads).