Skip to contentTopicauth
- The Login That Looked Fine (And Had Two Invisible Holes)June 15th, 2026
- How a Stale Assumption Kept Our Supabase Front Door Wide OpenJune 12th, 2026
- Ship It Ungated, Add Auth SecondMay 31st, 2026
- Your Middleware Isn't Enough: Mirror the Auth Check at the Route LayoutMay 14th, 2026
- How One Fresh Supabase Client Locked Out Every User I HadMay 9th, 2026
- Why Your Next.js Middleware Auth Redirect Is Silently Killing Your API RoutesMay 7th, 2026
- The NextAuth v5 Secret That Silently Breaks Your Fallback in ProductionMay 4th, 2026
- What a Cloudflare Tunnel 502 Taught Me About Robust OAuth CallbacksApril 29th, 2026
- The QuickBooks OAuth Bug That Worked Until It Didn'tApril 28th, 2026
- Stateless HMAC Auth in Next 16: The Quiet Rename That Burned MeApril 22nd, 2026
- The One-Liner That *Looked* Safe (and How an Origin Check Fixed It)April 13th, 2026
- The Auth Gate That Wasn't Guarding the Real DoorApril 6th, 2026