Dewfront, my weather app, went public at dewfront.com this week. Three high-severity holes opened the day it did, and none of them were in code I'd touched.
I'd designed and reviewed it for a backend that only listens on loopback, and the code comments said so, correctly. Then a commit put it on a public Cloudflare Tunnel, and every one of those assumptions went false at once.
The audit afterward found three. The webhook route took any URL with no auth and no private-range check, and the container runs on host networking, so a stranger could make my server send requests into my home network. The weather station ingest never checked the passkey its own protocol documents and trusted the reading's timestamp, so one POST dated 2030 could pin a forged reading as the latest observation for good. And the locations endpoint served full-precision coordinates to anyone, including 15-decimal browser location fixes from real visitors.
All three are fixed, deployed, and verified live. The same pass found three security headers defined in nginx and present on zero responses, because add_header doesn't carry into a location block that declares its own. One curl -I proved it.
Before I tunnel anything else I'll grep it for words like loopback, LAN only, and internal, and treat each one as a claim nobody has checked.
Source stays private for now. The case study is public.
