> Hardening ingestion of Cloudflare-generated configuration files in the same way we would for user-generated input

Yeah this seems like such a common source of failures for an organization of any size; you have things that you call separate components, but the developer of one trusts the others because the service boundary is "internal"

Developers do better work when integrating with a totally separate company when somebody is paying somebody else than they do on the interface between systems within the same company, because there are too many shortcuts they're tempted to make when a boundary doesn't feel like a real boundary

0

If you have a fediverse account, you can quote this note from your own instance. Search https://functional.cafe/users/chris__martin/statuses/115574685982477947 on your instance and quote it. (Note that quoting is not supported in Mastodon.)