Sign in

ilshadyX

@ilshadyx.bsky.social
94 followers 28 following 563 posts

Software Engineer & Builder Fundamentals over frameworks Youtube: youtube.com/@ilshadyx Codeless Sync - sync finance APIs to PostgreSQL codelesssync.com?utm_source=bluesky…

PostsRepliesMedia
ilshadyX @ilshadyx.bsky.social · 15m
"Worse is Better" explained why simple systems often win. Richard Gabriel argued that software that ships, spreads, and gets adopted beats software that’s technically superior. The better design may exist. The simpler one usually arrives first. #SoftwareEngineering #buildinpublic #webdevelopment
Worse is better
010
ilshadyX @ilshadyx.bsky.social · 22h
JWT logout is often an illusion. Deleting the token only removes it from the client. Any copied token still works until it expires. That’s the tradeoff of stateless auth: the server tracks nothing. The usual fix is a blocklist, which makes the system stateful again #SoftwareEngineering #Security
The JWT revocation problem
000
ilshadyX @ilshadyx.bsky.social · 30/09/2026
Dynamic programming is simpler than it sounds: never do the same work twice. A naive Fibonacci solution recomputes values again and again. Store each result once, then reuse it. The whole idea is finding repeated work and replacing it with a lookup #SoftwareEngineering #Algorithms #buildinpublic
120
ilshadyX @ilshadyx.bsky.social · 29/09/2026
Google’s AI search guide puts one thing above every tactic. Not schema. Not llms.txt. It’s content only you could create. Google calls it non-commodity content: insights, experience, and knowledge AI can’t easily reproduce. What that means for dev writing, in 4 ⬇️ #SoftwareEngineering #SEO
"Non-commodity content" in Google's AI search guide
100
ilshadyX @ilshadyx.bsky.social · 28/09/2026
If your site relies on client-side rendering, some AI crawlers may see a blank page. Google renders JavaScript. Many others don’t. Disable JavaScript and check what remains. If the content disappears, some crawlers may never see it. #SoftwareEngineering #SEO #buildinpublic
AI search engines struggle to see JavaScript
140
ilshadyX @ilshadyx.bsky.social · 27/09/2026
The fastest way to lose trust is a confident answer that’s wrong. “I don’t know yet” costs nothing. A bad guess can send multiple developers down the wrong path. The rule: if you’re guessing, say so. Uncertainty is cheaper than false certainty. #SoftwareEngineering #buildinpublic
050
ilshadyX @ilshadyx.bsky.social · 26/09/2026
My testing suite never validates the time it executes against. One hour between my local & the backend pushes any timestamp around midnight the incorrect side of that date boundary. Daily aggregates shift & nothing fails. Green proves one setup aligning with itself. #SoftwareEngineering
000
ilshadyX @ilshadyx.bsky.social · 25/09/2026
The most misunderstood part of SOLID is the S. Single Responsibility doesn’t mean “do one thing.” It means one reason to change. Two features may look related, but if different groups drive changes, they’re separate responsibilities. The reason for change matters. #SoftwareEngineering
Single Responsibility in SOLID
000
ilshadyX @ilshadyx.bsky.social · 25/09/2026
Don’t put tokens, passwords, or emails in URLs. HTTPS protects them in transit, not everywhere else. URLs end up in logs, history, and proxies. Sensitive data in a URL spreads fast. Use headers or the request body instead. #SoftwareEngineering #Security #buildinpublic
no secret within url
030
ilshadyX @ilshadyx.bsky.social · 23/09/2026
Solving Sudoku, you don’t fill all 81 squares and hope. You place a value, test it, and backtrack when it leads nowhere. That’s backtracking: exploring possibilities while pruning dead ends. The trick isn’t trying every path. It’s quitting bad ones early. #SoftwareEngineering #Algorithms
Backtracking algorithm
001
ilshadyX @ilshadyx.bsky.social · 23/09/2026
The urge to rewrite a messy codebase is usually a trap. That “bad” code contains years of edge cases and fixes. A rewrite doesn’t remove them. It rediscovers them in production. The mess is often the knowledge. #SoftwareEngineering #WebDevelopment #buildinpublic
020
ilshadyX @ilshadyx.bsky.social · 22/09/2026
Every SEO debate about Google clicks traces back to the 2024 API leak. What did it actually reveal? Three undocumented float fields: goodClicks, badClicks, and lastLongestClicks. That’s the evidence. Everything beyond that is interpretation. 5 receipts ⬇️ #SEO #SoftwareEngineering #buildinpublic
What the 2024 Google API leak & the court record actually say about click data
230
ilshadyX @ilshadyx.bsky.social · 22/09/2026
Greedy algorithms pick the best immediate option and never look back. That’s fast, but not always optimal. A locally good choice can block a better overall outcome. Greedy never fails to find an answer. It just may not find the best one. #SoftwareEngineering #Algorithms #buildinpublic
Greedy algorithm
030
ilshadyX @ilshadyx.bsky.social · 21/09/2026
The most dangerous regex is often the one validating user input. A crafted string can trigger catastrophic backtracking and lock a CPU core. Email and search validators are common targets. Don’t just distrust user input. Distrust the regex processing it. #SoftwareEngineering #Security
Danger of regex
000
ilshadyX @ilshadyx.bsky.social · 20/09/2026
100% test coverage rarely guarantees tested. It indicates each line executed once. A test might run a method, verify nothing, & the suite turns green. Coverage measures execution, not correctness. Test suites sit below 100%, & the defects that escape are inside covered paths regardless.
000
ilshadyX @ilshadyx.bsky.social · 18/09/2026
Postel’s Law said: be strict in what you send, lenient in what you accept The problem is compatibility debt. Accept a bad input once & someone will depend on it Soon the bug becomes the standard Modern protocol design favors stricter validation #SoftwareEngineering #WebDevelopment #buildinpublic
Postel's Law shaped the internet
040
ilshadyX @ilshadyx.bsky.social · 18/09/2026
Most sites skip basic security headers. CSP and HSTS are some of the cheapest defenses available. No code changes, just browser-enforced policy. Here are four headers worth using, plus the mistakes that quietly make them useless ⬇️ #SoftwareEngineering #Security #buildinpublic
Setting your security headers
130
ilshadyX @ilshadyx.bsky.social · 17/09/2026
Slack’s API can return 200 OK when the request actually failed. That breaks the contract status codes provide. Proxies, caches, & monitoring trust the HTTP code, not the JSON body. Hide errors behind 200 & systems stay green while users fail. Use the right status code. #SoftwareEngineering #API
Returning 200 with an error
000
ilshadyX @ilshadyx.bsky.social · 14/09/2026
Google ranks pages, not domains That’s why URL Rating (UR) is usually more useful than Domain Rating (DR). UR measures link strength for a page. DR measures domains A DR 70 site can still have pages nobody links to DR is potential. UR is where it shows up #SoftwareEngineering #SEO #buildinpublic
URL Rating
030
ilshadyX @ilshadyx.bsky.social · 13/09/2026
Story points often become time estimates in disguise. A 5-point task eventually gets translated back into days through velocity. The deadline stays the same. You’ve just added another layer. For solo work, estimating in days is usually simpler and more honest #SoftwareEngineering #WebDevelopment
000
ilshadyX @ilshadyx.bsky.social · 12/09/2026
"The code is self-documenting" typically translates to skipping docs. Inherited codebases reveal what happens, never why. The context behind this timeout & the load-bearing workaround is completely absent. Names explain the what. The why vanishes alongside whoever wrote it. #SoftwareEngineering
000
ilshadyX @ilshadyx.bsky.social · 11/09/2026
A Person class maps to a people table. No config required. That’s Convention over Configuration: sensible defaults so you only configure exceptions. More options mean more decisions. Good defaults remove work. The best default is the one users never notice. #SoftwareEngineering #WebDevelopment
Convention over Configuration
001
ilshadyX @ilshadyx.bsky.social · 10/09/2026
"dofollow" isn’t real. No HTML spec defines it. The only real attribute is nofollow. Google later changed it from a directive to a hint. Normal links remain the main way authority flows. Treating nofollow as a hard block relies on an outdated model. #SoftwareEngineering #SEO #buildinpublic
dofollow and nofollow attribute
020
ilshadyX @ilshadyx.bsky.social · 09/09/2026
Divide & Conquer powers many fast algorithms. Split a problem into smaller copies, solve each the same way, then combine the results Merge sort is the classic example: split, sort both halves, merge Find the right split & the solution often follows #SoftwareEngineering #Algorithms #buildinpublic
Divide and Conquer algorithm
020
ilshadyX @ilshadyx.bsky.social · 08/09/2026
Chrome deleted the padlock icon in 2023. Google's own study found 9 in 10 users read it as "this site is safe." It never meant that. HTTPS guarantees less than most devs assume. What TLS covers, what it doesn't, & the two holes to close on your own site ⬇️ #SoftwareEngineering #Security
HTTPS guarantees less than most developers assume
100
ilshadyX @ilshadyx.bsky.social · 07/09/2026
“Premature optimization is the root of all evil” is only half the quote. Knuth’s point: optimize after measuring, not before. Most “slow code” is an unprofiled bottleneck. Profile first, then fix what actually matters. #SoftwareEngineering #buildinpublic #webdevelopment
Premature optimization is the root of all evil
020
ilshadyX @ilshadyx.bsky.social · 07/09/2026
The way a team handles on-call says more about engineering health than any architecture diagram. Quiet rotations mean problems get fixed. Constant alerts mean firefighting became normal. The on-call pager is the real system diagram. #SoftwareEngineering #buildinpublic
140
ilshadyX @ilshadyx.bsky.social · 05/09/2026
Job listings demanding a "rockstar" who "thrives under pressure" aren't selling a real culture. They're just masking understaffing with a compliment attached. Rockstar translates to one developer doing three jobs. Thrives under pressure guarantees the crunch is permanent. #SoftwareEngineering
000
ilshadyX @ilshadyx.bsky.social · 04/09/2026
Make Illegal States Unrepresentable. Instead of checking for bad states, design them out. isLoading, hasError, and data can create impossible combinations. A single status: loading, success, or error cannot. Don’t catch invalid states. Make them impossible. #SoftwareEngineering #buildinpublic
Make Illegal States Unrepresentable
030
ilshadyX @ilshadyx.bsky.social · 03/09/2026
The old rule was “attackers don’t break in, they log in.” The 2026 Verizon DBIR says vulnerability exploitation has overtaken stolen credentials as the top entry path. Credentials still matter. Least privilege doesn’t stop the break-in, it limits how far it spreads. #SoftwareEngineering #Security
Principle of Least Privilege
000
ilshadyX @ilshadyx.bsky.social · 02/09/2026
Sliding Window is essential for fast code. Max sum of 5 consecutive numbers: naive re-adding costs 5,000 ops on 1,000 items. Sliding Window does 1 pass: add incoming, subtract outgoing. 5,000 ops become 1,000. The signal: "in a row". Slide a window #SoftwareEngineering #Algorithms #buildinpublic
Sliding window
040
ilshadyX @ilshadyx.bsky.social · 01/09/2026
API architecture shifts completely with serverless: it doesn't just change where your code runs, it changes how you have to write it. Here are four patterns a long-running server lets you ignore, & serverless forces you to face. #SoftwareEngineering #API #buildinpublic
Serverless api
231
ilshadyX @ilshadyx.bsky.social · 31/08/2026
The core of clean architecture is one home per data point. Violate this, and state bugs follow. Duplicates drift, causing systems to disagree with themselves. Never write sync logic. Eliminate duplicates by deriving values on the fly. #SoftwareEngineering #buildinpublic
Single source of truth
040
ilshadyX @ilshadyx.bsky.social · 30/08/2026
Building for millions you don’t have is a great way to never launch. Teams add Kubernetes, sharding, and microservices before they have users. Most products never reach that scale. Scale when scale is the problem. Until then, it’s procrastination. #SoftwareEngineering #buildinpublic
150
ilshadyX @ilshadyx.bsky.social · 29/08/2026
Most "best practices" are answers to problems you don't have yet. Copy the solution without the constraint that created it & all you get is complexity. A best practice without its context is just cargo cult. #SoftwareEngineering #WebDevelopment #buildinpublic
040
ilshadyX @ilshadyx.bsky.social · 28/08/2026
Most secret leaks aren’t hacks. They’re API keys in repos, images, or client bundles. Once a secret hits git, deleting it isn’t enough. Copies remain. Rotate it: revoke the old key and issue a new one. The leak isn’t the problem. A live leaked key is. #SoftwareEngineering #Security
Secret rotation security
010
ilshadyX @ilshadyx.bsky.social · 27/08/2026
Google says many AI SEO tactics don’t help. Its 2026 AI guide calls out llms.txt, AI rewrites, and content chunking. On llms.txt, Google says it neither helps nor hurts visibility. There was never an AI SEO hack. Just a market for selling one. #SEO #SoftwareEngineering #buildinpublic
Google recommends rejecting SEO tools
060
ilshadyX @ilshadyx.bsky.social · 26/08/2026
Two Pointers turns some O(n²) problems into O(n). For a sorted array, place one pointer at each end. If the sum is too big, move right. Too small, move left. Each step eliminates a range of possibilities. The clue is the sorted input. #SoftwareEngineering #Algorithms #buildinpublic
Two Pointers Algorithm
050
ilshadyX @ilshadyx.bsky.social · 25/08/2026
"Set the CORS origin to *" is the first fix everyone reaches for, & the advice against it is usually too blunt. The wildcard isn't the mistake. What you pair it with is. 4 things about CORS worth getting right ⬇️ #SoftwareEngineering #Security
CORS Origin security
100
ilshadyX @ilshadyx.bsky.social · 24/08/2026
Crashing on an error can make software more robust. That’s Fail Fast. The alternative is hiding errors and letting bad state spread. A silent failure becomes corrupt data or a harder bug later. Handle expected errors. Surface unexpected ones. #SoftwareEngineering #buildinpublic
Fail Fast principle
040
ilshadyX @ilshadyx.bsky.social · 23/08/2026
Most code review comments are nitpicks a linter should've caught. Spacing, naming, import order Meanwhile the wrong abstraction & the coupling you'll regret in six months sail straight through, because they're harder to spot We review what easy to comment on, not what matters #SoftwareEngineering
000
ilshadyX @ilshadyx.bsky.social · 22/08/2026
When someone asks how long a feature will take, I take my honest first guess & triple it. The coding was never the problem. It's the tests, the edge cases, the deploy, the thing that breaks downstream. The first number only covers writing it. #SoftwareEngineering #WebDevelopment #buildinpublic
040
ilshadyX @ilshadyx.bsky.social · 21/08/2026
getUser that also writes to the database. That breaks the Principle of Least Astonishment: code should do what its name suggests. The danger is hidden side effects. Everything works until getUser runs in a loop and starts hammering the database. Separate reads from writes. #SoftwareEngineering
The Principle of Least Astonishment
010
ilshadyX @ilshadyx.bsky.social · 20/08/2026
Images vs containers, the version that explains disappearing data An image is a blueprint. A container is a running copy with a temporary writable layer Destroy the container & that layer goes too If data must survive redeploys, put it in a volume, not the container #SoftwareEngineering #Docker
Use of Docker images & containers
000
ilshadyX @ilshadyx.bsky.social · 19/08/2026
Recursion solves a problem by calling itself on smaller pieces. The key is the base case. Without it, calls keep stacking until you hit a stack overflow. It fits naturally with trees, file systems, and divide-and-conquer problems. Use recursion when the data is nested. #SoftwareEngineering
Recursion
000
ilshadyX @ilshadyx.bsky.social · 18/08/2026
CSRF, cross-site request forgery, was a top web vulnerability for a decade, then quietly faded. The reason why is one of the better security stories out there. How it worked, & what killed it ⬇️ #SoftwareEngineering #Security #buildinpublic
CSRF faded
130
ilshadyX @ilshadyx.bsky.social · 17/08/2026
Inheritance looks like easy reuse. It’s also some of the tightest coupling you can write. A child class depends on its parent. Change the base and every subclass can break. Composition flips it: build from small pieces instead of extending a hierarchy you’re trapped in. #SoftwareEngineering
Composition over Inheritance
000
ilshadyX @ilshadyx.bsky.social · 16/08/2026
"We'll fix it later" is the most expensive sentence in software. Later never gets prioritised, because later never gets a deadline. The shortcut you took under pressure quietly becomes the permanent way it works. #SoftwareEngineering #WebDevelopment #buildinpublic
040
ilshadyX @ilshadyx.bsky.social · 15/08/2026
"How long will it take" has no honest answer, & engineers get punished for giving one anyway. The estimate becomes a deadline. The deadline becomes a promise. And every unknown you flagged when you said "about three days" is forgotten the moment something slips #SoftwareEngineering #WebDevelopment
010
ilshadyX @ilshadyx.bsky.social · 14/08/2026
user.account.profile.address..city looks handy. It’s really a chain of dependencies. That’s the Law of Demeter: don’t reach through objects for data you need. Each dot couples you to another internal structure. Ask the object for what you need instead. #SoftwareEngineering #buildinpublic
The Law of Demeter
040