forked from mattmakai/fullstackpython.com
- Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathweb-application-security.html
More file actions
Latest commit
137 lines (130 loc) · 7.53 KB
/
Copy pathweb-application-security.html
File metadata and controls
137 lines (130 loc) · 7.53 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
<!DOCTYPE html>
<htmllang="en"><head><metahttp-equiv="Content-Type" content="text/html; charset=UTF-8">
<metacharset="utf-8">
<metahttp-equiv="X-UA-Compatible" content="IE=edge">
<metaname="viewport" content="width=device-width, initial-scale=1.0">
<metaname="description" content="Full Stack Python shows how an entire Python web application is built and deployed. Each section of the guide explains a different key concept, from the server through the Python WSGI web framework to the front end JavaScript.">
<metaname="author" content="Matt Makai">
<linkrel="shortcut icon" href="theme/img/full-stack-python-logo-bw.png">
<title>Full Stack Python</title>
<!-- Bootstrap core CSS -->
<linkhref="theme/css/fsp.css" rel="stylesheet">
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<style>
html,
body {
font-size:18px;
color:#222;
background:#fefefe;
}
body {
padding-top:30px;
}
.footer {
padding:20px030px0;
}
a,a:hover {border-bottom:1px dotted; color:#444;}
a:hover {text-decoration: none; color:#000;}
.logo-title {font-size:56px; color:#403072; padding-top:80px;
font-family:"News Cycle","Arial Narrow Bold", sans-serif;
font-weight: bold; line-height:30px; margin-left:5px;}
.logo-titlea, .logo-titlea:hover {color:#000; text-decoration: none;
border-bottom: none;}
.logo-titlea:hover {color: gray;}
.logo-image {vertical-align: top; border: none;}
a.list-group-item.active {background:#444; border:1px solid #222;}
a.list-group-item.active:hover {background:#444; border:1px solid #222;}
#sidebar {margin-top:30px;}
@media (max-width:600px) {
.logo-header-section {
margin:20px32px00;
}
}
</style>
<scripttype="text/javascript">
var_gaq=_gaq||[];
_gaq.push(['_setAccount','UA-19910497-7']);
_gaq.push(['_trackPageview']);
(function(){
varga=document.createElement('script');ga.type='text/javascript';ga.async=true;
ga.src=('https:'==document.location.protocol ? 'https://ssl' : 'http://www')+'.google-analytics.com/ga.js';
vars=document.getElementsByTagName('script')[0];s.parentNode.insertBefore(ga,s);
})();
</script>
</head>
<body>
<ahref="https://github.com/makaimc/fullstackpython.github.com" class="github">
<imgstyle="position: absolute; top: 0; right: 0; border: 0;" src="http://s3.amazonaws.com/github/ribbons/forkme_right_darkblue_121621.png" alt="Fork me on GitHub" />
</a>
<divclass="container">
<divclass="row">
<divclass="col-md-12">
<divclass="logo-header-section">
<ahref="/" style="text-decoration: none; border: none;"><imgsrc="theme/img/full-stack-python-logo-bw.png" height="42" width="42" class="logo-image" /></a>
<spanclass="logo-title"><ahref="/">Full Stack Python</a></span>
</div>
</div>
</div>
<divclass="row">
<divclass="col-md-8">
<h1>Web Application Security</h1>
<p>Website security must be incorporated into building every level of the web
stack. However, I include a separate section here for topics that deserve
a comprehensive review such as firewalls, SSL certificates, and public key
authorization.</p>
<divclass="section" id="key-terms">
<h2>Key Terms</h2>
<p><em>Authorization</em> - specifying access rights and permissions to server and
application resources. For example, a non-logged in user can view a landing
page but only a logged in user can access an application's "account" screen.</p>
<divclass="section" id="security-resources">
<h3>Security Resources</h3>
<p><aclass="reference external" href="http://erik.io/blog/2013/06/08/a-basic-guide-to-when-and-how-to-deploy-https/">When and How to Deploy HTTPS</a></p>
<p><aclass="reference external" href="http://spenserj.com/blog/2013/07/15/securing-a-linux-server/">Securing a Linux Server</a></p>
<p><aclass="reference external" href="http://arstechnica.com/security/2013/02/securing-your-website-a-tough-job-but-someones-got-to-do-it/">Securing Your Website</a></p>
<p><aclass="reference external" href="http://blog.hartleybrody.com/https-certificates/">How HTTPS Secures Connections: What Every Web Dev Should Know</a></p>
<p>Open Web Application Security Project <aclass="reference external" href="https://www.owasp.org/index.php/Cheat_Sheets">(OWASP) Cheat Sheets for Security</a></p>
</div>
</div>
<br/>
Next read the
<ahref="/monitoring.html">monitoring</a> section.
</div>
<divclass="col-md-offset-1 col-md-3" id="sidebar">
<divclass="list-group">
<ahref="/introduction.html" class="list-group-item ">Introduction</a>
<ahref="/servers.html" class="list-group-item ">Servers</a>
<ahref="/operating-systems.html" class="list-group-item ">Operating Systems</a>
<ahref="/web-servers.html" class="list-group-item ">Web Servers</a>
<ahref="/platform-as-a-service.html" class="list-group-item ">Platform-as-a-service</a>
<ahref="/databases.html" class="list-group-item ">Databases</a>
<ahref="/wsgi-servers.html" class="list-group-item ">WSGI Servers</a>
<ahref="/web-frameworks.html" class="list-group-item ">Web Frameworks</a>
<ahref="/task-queues.html" class="list-group-item ">Task Queues</a>
<ahref="/static-content.html" class="list-group-item ">Static Content</a>
<ahref="/caching.html" class="list-group-item ">Caching</a>
<ahref="/web-browsers.html" class="list-group-item ">Web Browsers</a>
<ahref="/web-application-security.html" class="list-group-item active">Web Application Security</a>
<ahref="/monitoring.html" class="list-group-item ">Monitoring</a>
<ahref="/web-analytics.html" class="list-group-item ">Web Analytics</a>
<ahref="/api-integration.html" class="list-group-item ">API Integration</a>
<ahref="/source-control.html" class="list-group-item ">Source Control</a>
<ahref="/configuration-management.html" class="list-group-item ">Configuration Management</a>
<ahref="/dependency-management.html" class="list-group-item ">Application Dependencies</a>
<ahref="/no-sql-datastore.html" class="list-group-item ">NoSQL Data Stores</a>
<ahref="/about-author.html" class="list-group-item ">About</a>
<ahref="/change-log.html" class="list-group-item ">Change Log</a>
</div>
</div></div>
<hr/>
<divclass="footer pull-right">
<ahref="http://www.mattmakai.com/" class="underline">Matt Makai</a> 2014
</div>
</div>
<scriptsrc="http://code.jquery.com/jquery-2.1.0.min.js"></script>
<scriptsrc="theme/js/bootstrap.min.js"></script>
</body>
</html>