Journal
Writing
Opinionated engineering notes—security, scalability, correctness, and the interfaces between humans and machines. No listicles—just explanations you can reuse in prod and in interviews.
Filter
#API design#authentication#backend#backups#booking systems#caching#CDN#CI/CD#Cloudflare#concurrency#connection pooling#consensus#correctness#CORS#cPanel#cryptography#data consistency#data integrity#data migration#database connection#database migrations#date handling#decimal arithmetic#deployment#DirectAdmin#disaster recovery#distributed-systems#DNS#Docker#Edge#environment variables#Express#fallacies#FastAPI#file uploads#forms#Google Analytics 4#HTTP/2#image optimization#invoicing#JavaScript#JWT#Kubernetes#latency#messaging#Multer#Nepal VAT#networking#NetworkManager#Next.js#next/image#Nginx#Node.js#Nodemailer#OAuth#observability#passwords#performance#pg_restore#PM2#PostgreSQL#Prisma#production debugging#Python#query-plans#range types#React#Redis#refresh tokens#reliability#sagas#scaling#schema drift#schema management#Search Console#security#SEO#sessions#shared hosting#SMTP#SSE#staleness#storage#Tesseract OCR#time zones#TLS#transactions#Ubuntu#Vercel#web security#WebSocket#WordPress
Matching posts
Showing 3 of 35. Clear filters
- SecurityAugust 12, 20267 min read
JWT Access and Refresh Token Strategy
Design short-lived access tokens and rotating refresh-token sessions with revocation, browser protections, and key rotation.
JWTrefresh tokensauthenticationweb security - SecurityMay 7, 20268 min read
Hashing vs Encryption vs Encoding — The Differences Developers Must Understand
A production-minded map of encoding, hashing, and encryption—salts, passwords, JWTs, Base64 myths, interview answers, and the mistakes reviewers catch.
cryptographypasswordsJWTbackend - SecurityApril 2, 20262 min read
JWT authentication without mythology — rotations, revocation, and session ergonomics
Symmetric versus asymmetric verification, JWKS fleets, leaky storage pitfalls, and when opaque cookies outperform bearer tokens.
JWTsessionsOAuthAPI design