Lesson 49 of 60 · Go
Security Best Practices – Input Validation & Secrets
Duration: 20 minutes
Secure Coding
This lesson explains the main concept clearly with beginner-friendly examples and background so you can learn why the code works.
- Validate all external input (JSON, query params, headers).
- Escape HTML (
html/template). - Use constant‑time comparison for secrets (
subtle.ConstantTimeCompare).
if subtle.ConstantTimeCompare([]byte(provided), []byte(expected)) != 1 {
http.Error(w, "invalid", http.StatusUnauthorized)
}
- Never log secrets.
- Prefer
crypto/randfor generating random tokens.
b := make([]byte, 32)
_, err := rand.Read(b) // cryptographically secure
Dependency scanning
$ go list -m -u all # list newer versions
$ govulncheck ./... # GitHub's vulnerability scanner