Sign in

jub0bs

@jub0bs.com
2.4K followers 276 following 469 posts

infosec enthusiast • Go dev & trainer • contributor to the Go project • minimalist • chaotic good • trying to make sense of the Web • he/him Blog: jub0bs.com Free Go course: github.com/jub0bs/go-course-beginner Free 🇵🇸! Leave 🇱🇧 alone!

PostsRepliesMedia
jub0bs @jub0bs.com · 31/01/2026
⚡Middleware execution during preflight is now faster and incurs fewer heap allocations.
A screenshot of benchmark results pitting github.com/jub0bs/cors against github.com/rs/cors. The results are available at https://github.com/jub0bs/cors-benchmarks.
100
jub0bs @jub0bs.com · 31/01/2026
😇 The library's API is now simpler. pkg.go.dev/github.com/j...
A screenshot of github.com/jub0bs/cors's documentation, available at https://pkg.go.dev/github.com/jub0bs/cors#pkg-index.
220
jub0bs @jub0bs.com · 31/01/2026
💣 This release brings a couple of simplifying but potentially breaking changes. None of them is very likely to affect you. github.com/jub0bs/cors/...
A snapshot of the changelog for v0.11.0 of github.com/jub0bs/cors, available at https://github.com/jub0bs/cors/blob/v0.11.0/CHANGELOG.md.
110
jub0bs @jub0bs.com · 16/06/2025
💡 Did you know that you can craft URLs that bypass X/Twitter's URL shortener (t[.]co) and domain deny list? For instance, try sharing x.com/login?redire... in a tweet and clicking the link; you will ultimately be redirected to ddosecrets.com (which is banned by X) without ever traversing t[.]co!
The "Avoiding" meme (featuring an agent from The Matrix dodging bullets at an insane speed), with the caption "Me trying to avoid t.co".
160
jub0bs @jub0bs.com · 04/06/2025
FWIW, here is a snapshot of a slide from my introductory course:
Did Go push error handling too far?

Many newcomers perceive error handling in Go as verbose, tedious, and repetitive. In most cases, that's because they haven't been handling failures properly in their programs before coming to Go.

Go, rather than sweeping failure cases under the rug, forces you to think about them and eliminate them as you go. It compels you to be cautiously pessimistic.

This approach arguably is a strength of the language. Many software outages can indeed be attributed to improper error handling.

You may hate Go's error handling right now but, in time, you will grow to love it!

(artwork by Egon Elbre, based on the original design by Renée French, of the Go Gopher holding a red heart)
010
jub0bs @jub0bs.com · 28/05/2025
This is the kind of stuff that "optics" conjures up in my mind when I chance upon it in a news article. Nothing else. 🤷
A ray-tracing diagram for a converging lens (borrowed from https://en.wikipedia.org/wiki/Optics#/media/File:Lens3b.svg).
000
jub0bs @jub0bs.com · 14/02/2025
Initialising a #CORS middleware has been steadily getting faster and less memory-hungry in recent versions of github.com/jub0bs/cors, as shown by this chart (lower is better). 😇 #golang
Bar chart showing that initialising a CORS middleware with github.com/jub0bs/cors has been getting faster and less memory-hungry between v0.5.1 and v0.5.5.
161
jub0bs @jub0bs.com · 09/12/2024
Go's logo may strike you as uninspired and unremarkable. I'm guessing that the manga-style speed lines are meant to convey that the language is intended for "programming at scale". Right?
Six variations (in different colours) of the Go programming language's logo, which consists in the word "Go" (in upper case) preceded by three horizontal manga-style speed lines.
120
jub0bs @jub0bs.com · 21/11/2024
Introduce yourself with four video games. bsky.app/profile/eric...
a screenshot of Prince of Persia (1989)a screenshot of Donkey Kong Country 3 (1996)a screenshot of Diablo (1996)an artwork for Left 4 Dead 2 (2009)
040
jub0bs @jub0bs.com · 19/07/2024
Un meme Dragon Ball Z qui montre Sangoten ("Ses jours ne sont pas comptés.") et Trunks ("Sa vie n'est pas en danger.") tenter une fusion qui au final échoue ("Ses jours ne sont pas en danger.").
010
jub0bs @jub0bs.com · 10/04/2024
It turns out that rs/cors (Go's most popular CORS middleware library) allocates a lot of memory in response to some malicious unauthenticated requests. 😬
benchmark results showing that rs/cors (contrary to jub0bs/cors) allocates an inordinate amount of memory in response to some requests
100
jub0bs @jub0bs.com · 08/08/2023
Here is a Go challenge for you! 🤓 Without modifying my package named "puzzler", can you create, in the main function, a variable of (non-exported) type puzzler.config? Playground: go.dev/play/p/hSSRfbZbjKK I'll post a solution tomorrow. 😉
A Go challenge whose objective is to declare, in the main function, a variable of a type non-exported by a library package.
210
jub0bs @jub0bs.com · 08/08/2023
NaNs and maps don't mix well, but Go 1.21's upcoming 'clear' builtin function will allow us to properly delete all keys from a map (including keys that are not reflexive for equality). This is likely to prove particularly useful in generic code. go.dev/play/p/eoiTQq3YgJ4?v=gotip
A code snippet in Go that demonstrates how, contrary to maps.Clear, the new clear function allows you to delete all keys from a map.
021