API-Security-Checklist
API-Security-Checklist copied to clipboard
Suggestion: Always set charset in response header
http://blog.portswigger.net/2016/11/json-hijacking-for-modern-web.html
Also contains other helpful hints too
Anyone want to create a PR for this?