Is your API or SPA leaking sensitive data?
Check what data your app sends to the browser or returns in an API. You may be surprised just how much you're accidently sharing... (Hint: Usually more than you realise!)
https://securinglaravel.com/p/security-tip-fix-your-leaky-apis#Laravel#PHP