<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Dimitry Toronto Moscow</title>
    <description>The latest articles on DEV Community by Dimitry Toronto Moscow (@dimitry_torontomoscow_20).</description>
    <link>https://dev.to/dimitry_torontomoscow_20</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4156309%2Fce213887-ab9c-435e-90ea-753ed3130b9b.jpg</url>
      <title>DEV Community: Dimitry Toronto Moscow</title>
      <link>https://dev.to/dimitry_torontomoscow_20</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/dimitry_torontomoscow_20"/>
    <language>en</language>
    <item>
      <title>CSP Report-Only is a safer first step than guessing an enforcement policy</title>
      <dc:creator>Dimitry Toronto Moscow</dc:creator>
      <pubDate>Fri, 02 Oct 2026 05:09:30 +0000</pubDate>
      <link>https://dev.to/dimitry_torontomoscow_20/csp-report-only-is-a-safer-first-step-than-guessing-an-enforcement-policy-22e4</link>
      <guid>https://dev.to/dimitry_torontomoscow_20/csp-report-only-is-a-safer-first-step-than-guessing-an-enforcement-policy-22e4</guid>
      <description>&lt;p&gt;I wanted a less dramatic way to start reviewing security headers on small sites.&lt;/p&gt;

&lt;p&gt;The usual advice jumps from “your headers need work” to a copied CSP that breaks analytics, fonts, embeds, or a login flow. That is not a great deployment plan. Content Security Policy is tied to the application’s real dependencies, so a policy that looks tidy in a snippet can still be wrong for the site running it.&lt;/p&gt;

&lt;p&gt;So I built &lt;strong&gt;HeaderKit&lt;/strong&gt;: a $29 one-time pack oriented around &lt;strong&gt;CSP Report-Only&lt;/strong&gt; and common security headers. You review and apply the recommendations yourself. Nothing auto-enforces a CSP on your site.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Report-Only changes
&lt;/h2&gt;

&lt;p&gt;A Report-Only policy lets a browser report violations without using the policy to block the resource. That makes it useful for discovering what the application actually loads before deciding whether enforcement is appropriate.&lt;/p&gt;

&lt;p&gt;A small example is in this gist:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://gist.github.com/dimonch-byte/d486c361974e0ff63d5f586f4894da79" rel="noopener noreferrer"&gt;View the HeaderKit example&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;It includes a &lt;code&gt;Content-Security-Policy-Report-Only&lt;/code&gt; example plus headers such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;code&gt;X-Content-Type-Options: nosniff&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;Referrer-Policy: strict-origin-when-cross-origin&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;Permissions-Policy&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;X-Frame-Options&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The CSP example includes a placeholder report collector. That placeholder is intentional: reporting only helps if you choose a collector you control and understand what it receives. Do not paste a sample policy into production unchanged and assume it matches your framework or third-party services.&lt;/p&gt;

&lt;h2&gt;
  
  
  A practical review loop
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Inventory the scripts, styles, images, fonts, frames, and network calls your site really uses.&lt;/li&gt;
&lt;li&gt;Start with Report-Only and watch the violations during normal flows, including login and checkout if applicable.&lt;/li&gt;
&lt;li&gt;Remove dependencies you do not need, or decide explicitly which origins are trusted.&lt;/li&gt;
&lt;li&gt;Tighten the policy in stages, with a rollback path.&lt;/li&gt;
&lt;li&gt;Only consider enforcement after testing the application—not because a scanner produced a nice grade.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Nonces, hashes, inline styles, third-party analytics, payment widgets, and embedded video all change the answer. There is no universal “copy these headers” block that can account for every stack.&lt;/p&gt;

&lt;h2&gt;
  
  
  What HeaderKit is not
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Not a WAF.&lt;/strong&gt; It does not inspect or filter arbitrary traffic.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Not automatic CSP enforcement.&lt;/strong&gt; You choose what to deploy and when.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Not a compliance certification.&lt;/strong&gt; A header pack cannot certify an application or organization.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Not a promise of an A or A+ scanner score.&lt;/strong&gt; Results depend on your stack and the configuration you actually ship.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The goal is a reviewable starting point, not a lockdown claim. If you want to see the sample before deciding whether the workflow fits, the gist is public.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://headerkit.adjudi.com/?utm_source=devto&amp;amp;utm_medium=organic&amp;amp;utm_campaign=headerkit-2026-10-02" rel="noopener noreferrer"&gt;HeaderKit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gist.github.com/dimonch-byte/d486c361974e0ff63d5f586f4894da79" rel="noopener noreferrer"&gt;Example CSP Report-Only headers&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>webdev</category>
      <category>security</category>
      <category>performance</category>
      <category>devops</category>
    </item>
    <item>
      <title>I wanted deny rules for common leak paths — not a zip of someone’s secrets</title>
      <dc:creator>Dimitry Toronto Moscow</dc:creator>
      <pubDate>Fri, 02 Oct 2026 05:09:17 +0000</pubDate>
      <link>https://dev.to/dimitry_torontomoscow_20/i-wanted-deny-rules-for-common-leak-paths-not-a-zip-of-someones-secrets-5hg6</link>
      <guid>https://dev.to/dimitry_torontomoscow_20/i-wanted-deny-rules-for-common-leak-paths-not-a-zip-of-someones-secrets-5hg6</guid>
      <description>&lt;p&gt;I kept seeing the same uncomfortable class of deployment mistake: a production host that still answers for &lt;code&gt;.git&lt;/code&gt;, &lt;code&gt;.env&lt;/code&gt;-shaped paths, source maps, or an old backup archive.&lt;/p&gt;

&lt;p&gt;The useful question is usually not “can I retrieve something interesting?” It is “are these paths reachable on a site I control, and what can I put in front of them before the next deploy?”&lt;/p&gt;

&lt;p&gt;So I built &lt;strong&gt;LeakDeny&lt;/strong&gt;: paste a URL you control → run a proof-style check → pay once → download a deny pack for common exposure paths. The pack is $29 one-time.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the pack is for
&lt;/h2&gt;

&lt;p&gt;LeakDeny is deliberately narrow. It gives you host-level snippets and verification steps for patterns such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;.git&lt;/code&gt; and similar repository paths&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;.env&lt;/code&gt;-shaped paths&lt;/li&gt;
&lt;li&gt;JavaScript source maps (&lt;code&gt;.map&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;backup archives and database dumps&lt;/li&gt;
&lt;li&gt;a few common backup-file patterns&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The public example gist has nginx and Caddy versions:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://gist.github.com/dimonch-byte/ed7cbc77378a94585210f26cf17de3f9" rel="noopener noreferrer"&gt;See the example deny snippets&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The intended workflow is boring, which is good: review the generated rules, apply them in the layer you actually operate, reload or redeploy, and verify that the paths return a denial response rather than &lt;code&gt;200 OK&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;For example, the check after deployment should be something like:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-sI&lt;/span&gt; https://your-domain.example/.git/HEAD
curl &lt;span class="nt"&gt;-sI&lt;/span&gt; https://your-domain.example/.env
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The exact status and routing depend on your host, proxy, CDN, and configuration. A &lt;code&gt;404&lt;/code&gt; or &lt;code&gt;403&lt;/code&gt; can be the desired result, but it is not proof that a file was never exposed in the past.&lt;/p&gt;

&lt;h2&gt;
  
  
  What it does not do
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;It is &lt;strong&gt;not&lt;/strong&gt; a WAF.&lt;/li&gt;
&lt;li&gt;It is &lt;strong&gt;not&lt;/strong&gt; a bug-bounty scanner for strangers’ domains.&lt;/li&gt;
&lt;li&gt;It does not remove a secret that was already committed or downloaded.&lt;/li&gt;
&lt;li&gt;It does not rotate credentials for you.&lt;/li&gt;
&lt;li&gt;It does not claim that a few deny rules equal a complete security review.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If a credential may have been exposed, rotate or revoke it separately. Blocking &lt;code&gt;/.env&lt;/code&gt; today does not make an old leaked token safe. Likewise, a deny rule is only useful if it is actually applied at the right layer and tested after a CDN or framework change.&lt;/p&gt;

&lt;p&gt;I also made a conscious decision about the proof asset: &lt;strong&gt;LeakDeny never packages secret contents&lt;/strong&gt;. The example gist contains path rules only. I would rather publish a small, reviewable configuration fragment than turn a security check into a mechanism for collecting or redistributing someone’s data.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://leakdeny.adjudi.com/?utm_source=devto&amp;amp;utm_medium=organic&amp;amp;utm_campaign=leakdeny-2026-10-02" rel="noopener noreferrer"&gt;LeakDeny&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gist.github.com/dimonch-byte/ed7cbc77378a94585210f26cf17de3f9" rel="noopener noreferrer"&gt;Example nginx/Caddy gist&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Use it on a URL you own or are authorized to test. If your stack is Cloudflare, a managed host, or something other than nginx/Caddy, treat the pack as a starting point and translate the intent into the controls your platform actually supports.&lt;/p&gt;

</description>
      <category>security</category>
      <category>devops</category>
      <category>nginx</category>
      <category>webdev</category>
    </item>
    <item>
      <title>Your site has no clean brief for AI agents — so I shipped a $19 four-file pack</title>
      <dc:creator>Dimitry Toronto Moscow</dc:creator>
      <pubDate>Fri, 02 Oct 2026 04:47:41 +0000</pubDate>
      <link>https://dev.to/dimitry_torontomoscow_20/your-site-has-no-clean-brief-for-ai-agents-so-i-shipped-a-19-four-file-pack-4e8h</link>
      <guid>https://dev.to/dimitry_torontomoscow_20/your-site-has-no-clean-brief-for-ai-agents-so-i-shipped-a-19-four-file-pack-4e8h</guid>
      <description>&lt;p&gt;I kept needing a &lt;strong&gt;short, honest brief&lt;/strong&gt; for AI tools crawling a small site — not another SEO dashboard, and not a promise that ChatGPT will cite me.&lt;/p&gt;

&lt;p&gt;So I built &lt;strong&gt;CiteKit&lt;/strong&gt;: paste a public URL → free check → preview four files → $19 one-time zip via Paddle.&lt;/p&gt;

&lt;h2&gt;
  
  
  What you get
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Spec-shaped &lt;code&gt;/llms.txt&lt;/code&gt; (editorial map, not a sitemap dump)&lt;/li&gt;
&lt;li&gt;Organization + FAQPage &lt;code&gt;schema.jsonld&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;FAQ drafts (&lt;code&gt;faq.md&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;Stack README&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  What it is &lt;strong&gt;not&lt;/strong&gt;
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Not rankings&lt;/li&gt;
&lt;li&gt;Not “get cited by ChatGPT/Perplexity”&lt;/li&gt;
&lt;li&gt;Not citation monitoring&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;/llms.txt&lt;/code&gt; is a community convention, not a guarantee&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Who it’s for
&lt;/h2&gt;

&lt;p&gt;Indie / small marketing sites (Next.js, Framer, Webflow, Carrd, Ghost, static hosts) that don’t already emit this via Yoast / Mintlify / GitBook.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Site: &lt;a href="https://citekit.adjudi.com/?utm_source=devto&amp;amp;utm_medium=organic&amp;amp;utm_campaign=citekit-2026-10-02&amp;amp;utm_content=article" rel="noopener noreferrer"&gt;citekit.adjudi.com&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Example &lt;code&gt;/llms.txt&lt;/code&gt; shape: &lt;a href="https://gist.github.com/dimonch-byte/1c0e50c793c85239b3f03e7392bd5f7d" rel="noopener noreferrer"&gt;https://gist.github.com/dimonch-byte/1c0e50c793c85239b3f03e7392bd5f7d&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Operator: 9213651 Canada Inc. · Support: &lt;a href="mailto:idealstoronto@gmail.com"&gt;idealstoronto@gmail.com&lt;/a&gt; · MoR: Paddle&lt;/p&gt;

</description>
      <category>ai</category>
      <category>webdev</category>
      <category>indiehackers</category>
      <category>tooling</category>
    </item>
  </channel>
</rss>
