Posts
All the articles I've posted.
-
From 'I Can't Click' to a Full Testing Harness: How We Built Playwright for the Terminal
How a frustrating limitation in TUI testing led to building a scripted interaction system that lets AI agents drive a terminal editor like Playwright drives a browser.
-
I built a terminal IDE that feels like VS Code: here's why
TTT is a terminal-native IDE written in Go with standard keybindings, LSP support, and a familiar GUI feel, built so you never have to leave the terminal.
-
Making OAuth Testable: Rethinking OIDC Clients in JavaScript
How separating protocol logic from runtime concerns makes OAuth testable without mocks, using a functional core and thin framework adapters tested against a real identity provider.
-
What 200 Concurrent Users Taught Me About SQLite Performance
How profiling on the wrong machine led me down a week-long detour, and how WAL mode and a read/write pool split more than doubled throughput in Autentico.
-
I Found 5 Security Bugs in My OAuth2 Provider on My First Try (With an MCP Security Tool)
How connecting go-appsec/toolbox to Claude Code revealed five vulnerabilities in Autentico, including a HIGH severity unauthenticated token introspection issue, on the very first session.
-
Why I Built an Identity Provider in Go and SQLite
How and why I built Autentico, a self-contained, single-binary OIDC provider backed by SQLite that removes the ceremony from identity management.
-
Adding ABAC Authorization to a Real-Time Collaborative App with OpenTDF
How I added attribute-based access control to Skedoodle, an open-source real-time collaborative sketching app, using OpenTDF. Covering database-backed sharing, WebSocket enforcement, and centralized ABAC policy decisions, all built in a single afternoon with an AI coding agent.
-
Type-Level Library Dependency Injection. Let the Consumer App Define the API
A look at how three TypeScript primitives you already have can eliminate an entire class of silent runtime bugs across feature flags, translations, environment variables, and design tokens — with no codegen, no CLI, and no type engine.
-
The Art of Juggling Tech Debt While Shipping Features
A practical, friendly guide to handling bugs, tech debt, and unexpected issues during feature development without losing your mind.
-
JavaScript Proxy and Reflect API: Intercepting Object Operations
Deep dive into JavaScript Proxy and Reflect API for intercepting object operations, with practical examples of validation, logging, and computed properties