The archive

2026

11 essays filed in 2026, from 4 writers. Most-covered topic: #case study.

Essays
11
Writers
4
First filed
Jul 11
Latest
Sep 14
Words published
19310
Top topic
#case study
  1. aws

    Closing the Rate-Limit Bypass: A CloudFront + ALB Case Study

    How we closed an `X-Forwarded-For` spoofing bypass on an AWS WAF rate-limit rule — CloudFront custom secret header, ALB origin verification, and a composite-key rate-based rule that actually counts real clients.

    10 min
  2. express

    Replacing a Wildcard CORS Policy: An Express Allowlist Case Study

    How we replaced a permissive Express `cors` regex with a strict allowlist — escaped-dot origin matching, `Vary: Origin` on every response, and no more CWE-942 finding on the pen-test report.

    8 min
  3. aws

    Cutting the File-Upload Bill: A Cognito + S3 Case Study

    How we replaced a hosted upload widget with native Cognito and S3, kept the browser uploading straight to the bucket, and brought the monthly invoice down.

    10 min
  4. backend

    Upgrading TypeORM 0.3 to 1.0 in Production: A NestJS Case Study

    How we took TypeORM 0.3 → 1.0 to a live NestJS API without a headache.

    8 min
  5. aws

    How a CloudFront Custom Error Page Leaked JWTs to S3: A Case Study

    A pen-test curl found CloudFront forwarding `Authorization` headers to the S3 error-page bucket, where S3 reflected every JWT back in its XML error response. Two lines of Terraform closed it across sixteen distributions.

    12 min
  6. email

    Implementing a Zero Auth Unsubscribe Link on Your Email

    Nobody logs in to unsubscribe. They mark you as spam instead. Here's the small trick we used — a signed token in the URL — so users can unsubscribe with one tap without ever seeing a login screen.

    6 min
  7. backend

    Splitting a Mega-Service Into Four: The Service-Facade Refactor (Plus a Reusable Skill)

    How we split a 1,307-line `user.service.ts` into four responsibility-tagged NestJS sub-services (query, mutation, membership, stats) behind a stable facade — no caller broke, no test changed, one PR, and a reusable Claude skill file at the end.

    8 min
  8. remote

    Iftar at Apetit: The Sarajevo Team Picks a Menu

    One evening in March the Sarajevo Clearviewers sat down for a Ramadan iftar dinner. The Slack thread that got us to the table is the honest picture of how the team actually organizes itself: informal, patient, and mostly saying 'svejedno.'

    6 min
  9. jwt

    How a JWT Audience Map Saved a CORS Mistake: A Defense-in-Depth Case Study

    On a client's API, a CORS wildcard looked like a HIGH severity finding — until we tried to actually exploit it. A second, independent JWT audience check turned a trivially exploitable bug into one that required a much harder prerequisite.

    7 min
  10. react native

    Asking For Notification Permission: The Second Time Is the Wrong Time

    iOS gives you exactly one shot at the native permission prompt. Here's the simple screen we show first, so users see what they'll get before the OS asks the question.

    8 min
  11. devsecops

    From DevOps to DevSecOps: How I Became Clearview's In-House Pen-Tester

    How we built an in-sprint pen-tester role into every engagement — the DevSecOps handoff, the two decades of DevOps that led to it, and the OWASP Top 10 categories that show up first in real client APIs.

    11 min
Type to search. ↑↓ to navigate. Enter to open. Esc to close.