The WAF is in good condition, this is my starting point: shadow mode with reporting, replay of captured traffic bot detection (fingerprint header) intel threats (AbuseIPDB, AlienVault) GraphQL: depth, complexity, batch, introspection OpenAPI: request validation against specs WASM plugin in sandbo...
Source: [Hacker News](https://github.com/theghostshinobi/shibuya)