-To guard against this, it is advisable to avoid framing a comparision +To guard against this, it is advisable to avoid framing a comparison where both sides are untrusted user inputs. Instead, use a configuration to store and access the values required.
-The following example shows a comparision where both the sides -are from attacker controlled request headers. This should be avoided.: +The following example shows a comparison where both the sides +are from attacker-controlled request headers. This should be avoided.:
@@ -24,12 +24,4 @@ One way to remedy the problem is to test against a value stored in a configurati