From password rules to token handling, security often takes more time than expected. Small mistakes in authentication can lead to serious security issues, and applying security standards correctly (e.g., OWASP) in real projects is not always easy. How do you handle it?