[{"data":1,"prerenderedAt":23},["ShallowReactive",2],{"blog-category-diagrams":3},[4,10,15,19],{"path":5,"title":6,"description":7,"date":8,"readTime":9},"/blog/diagrams/csrf-who-attaches-the-cookie","CSRF: Who Actually Attaches the Cookie (Diagram)","A sequence diagram of a CSRF attack, showing the step everyone misses: the victim's own browser attaches the session cookie, so nothing has to be stolen.","2026-07-31","4 min read",{"path":11,"title":12,"description":13,"date":8,"readTime":14},"/blog/diagrams/supabase-key-trust-boundary","Supabase Keys and the Trust Boundary (Diagram)","A diagram of what your publishable key and secret key can each reach in Supabase, and why only one of them gets checked by Row Level Security.","3 min read",{"path":16,"title":17,"description":18,"date":8,"readTime":9},"/blog/diagrams/vibe-coded-trust-boundary","Where the Trust Boundary Sits in a Vibe-Coded App (Diagram)","A diagram of the single line that decides what an attacker can read in an app built with Lovable, Bolt, v0 or Cursor, and what stays private.",{"path":20,"title":21,"description":22,"date":8,"readTime":9},"/blog/diagrams/which-api-key-goes-where","Which API Key Goes Where (Diagram)","A decision tree for telling a browser-safe API key from one that has to stay on your server, starting from the characters the key begins with.",1785543193870]