Archive

#System Design

Stop Leaking Secrets: How to Catch Security Flaws Before Your Pull Request

Finding security vulnerabilities and exposed API keys during pull request reviews or CI/CD pipelines causes unnecessary rework and security risks. This guide explains how to implement "Shift-Left Security" by running static application security testing (DevSkim) alongside dedicated secret scanning (Gitleaks) directly on your local workstation using Git pre-commit hooks. By catching insecure coding patterns and credentials the moment you commit, you eliminate awkward PR reviews and prevent leaks before they ever enter Git history.

From Lost Paper Receipts to One-Tap Profit: How I Built a Custom App for a Cab Driver

Independent taxi drivers juggling multiple aggregators like Uber, Ola, Rapido, and offline private bookings face daily accounting chaos, often relying on paper slips that get misplaced. This case study documents the end-to-end development of SD Travels (Driver Portal)—a lightweight, driver-centric mobile app engineered to deliver instant net-profit visibility, quick single-tap entries for fares, CNG refills, and maintenance, and reliable offline-first local data persistence. Within its first week of real-world use, the app completely eliminated month-end bookkeeping guesswork and provided effortless, real-time daily profit tracking

New HTTP QUERY Method Changes Everything

A 2026 internet standard that introduces the HTTP QUERY method to resolve long-standing limitations in API design. This new method is safe and idempotent, meaning it performs read-only operations that can be retried without side effects. Unlike GET, which is restricted by URL length limits and security risks, QUERY can transmit large, complex data structures within a request body. It improves upon the common POST workaround by allowing responses to be cached at the network edge using a key based on the request content. While server-side support is emerging in frameworks like Node.js and Fastify, the sources note that full browser and infrastructure integration is still ongoing.