Nimbleparsec for user input?

Oh, that’s very bad practice … This way you instruct attacker that this was already spotted. You should wait some time, so the attacker only wastes time and resources waiting for reply. If you would simulate a “positive” response without telling the attacker that his attack was spotted then he may try again and again waste time and resources. Didn’t working on security devops stuff for years, but if I remember correctly you have to return 400 error response after few seconds of waiting or something like that …