Rails Security in Times of AI-Driven Scanners
AI-driven scanners now probe small Rails apps for credentials and known exploits. How I use Rack::Attack, fail2ban, Cloudflare, and AI audits to fight back.
Where I share what I'm exploring in software development, Ruby on Rails, AI, and everything in between.
AI-driven scanners now probe small Rails apps for credentials and known exploits. How I use Rack::Attack, fail2ban, Cloudflare, and AI audits to fight back.
A pause between parts 7 and 8: four places where running nexo_mail against a real inbox forced the design past what the earlier posts described.
Why the merge, dedupe and narration of three email extractions lives in a Nexo skill rather than in Ruby, and the seam for fixing model arithmetic.
Nexo's four sandbox tiers and four permission modes, and how an email agent gets write access to one folder and nothing else, enforced in code.
Fan three email source agents out with Nexo.concurrent: bounded concurrency, ordered results, and a sequential fallback when the async gem is missing.