<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Hassam Fathe Muhammad</title>
    <description>The latest articles on DEV Community by Hassam Fathe Muhammad (@hassamdev).</description>
    <link>https://dev.to/hassamdev</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1806185%2Fe33362af-9a2c-4341-9915-76889ff7c1fa.jpg</url>
      <title>DEV Community: Hassam Fathe Muhammad</title>
      <link>https://dev.to/hassamdev</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/hassamdev"/>
    <language>en</language>
    <item>
      <title>[Boost]</title>
      <dc:creator>Hassam Fathe Muhammad</dc:creator>
      <pubDate>Tue, 04 Aug 2026 19:05:47 +0000</pubDate>
      <link>https://dev.to/hassamdev/-1ah1</link>
      <guid>https://dev.to/hassamdev/-1ah1</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/hassamdev/building-a-secure-websocket-based-customer-support-chat-chat-policies-rate-limiting-and-bola-4f4g" class="crayons-story__hidden-navigation-link"&gt;Building a Secure WebSocket-Based Customer Support Chat: Chat Policies, Rate Limiting, and BOLA Prevention&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/hassamdev" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1806185%2Fe33362af-9a2c-4341-9915-76889ff7c1fa.jpg" alt="hassamdev profile" class="crayons-avatar__image" width="800" height="970"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/hassamdev" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Hassam Fathe Muhammad
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Hassam Fathe Muhammad
                
              
              &lt;div id="story-author-preview-content-4311960" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/hassamdev" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1806185%2Fe33362af-9a2c-4341-9915-76889ff7c1fa.jpg" class="crayons-avatar__image" alt="" width="800" height="970"&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Hassam Fathe Muhammad&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/hassamdev/building-a-secure-websocket-based-customer-support-chat-chat-policies-rate-limiting-and-bola-4f4g" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Aug 4&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/hassamdev/building-a-secure-websocket-based-customer-support-chat-chat-policies-rate-limiting-and-bola-4f4g" id="article-link-4311960"&gt;
          Building a Secure WebSocket-Based Customer Support Chat: Chat Policies, Rate Limiting, and BOLA Prevention
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/websocket"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;websocket&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/cybersecurity"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;cybersecurity&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/node"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;node&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/typescript"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;typescript&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
            &lt;a href="https://dev.to/hassamdev/building-a-secure-websocket-based-customer-support-chat-chat-policies-rate-limiting-and-bola-4f4g#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              &lt;span class="hidden s:inline"&gt;Add&amp;nbsp;Comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            3 min read
          &lt;/small&gt;
            
              &lt;span class="bm-initial crayons-icon c-btn__icon"&gt;
                

              &lt;/span&gt;
              &lt;span class="bm-success crayons-icon c-btn__icon"&gt;
                

              &lt;/span&gt;
            
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>Building a Secure WebSocket-Based Customer Support Chat: Chat Policies, Rate Limiting, and BOLA Prevention</title>
      <dc:creator>Hassam Fathe Muhammad</dc:creator>
      <pubDate>Tue, 04 Aug 2026 10:50:06 +0000</pubDate>
      <link>https://dev.to/hassamdev/building-a-secure-websocket-based-customer-support-chat-chat-policies-rate-limiting-and-bola-4f4g</link>
      <guid>https://dev.to/hassamdev/building-a-secure-websocket-based-customer-support-chat-chat-policies-rate-limiting-and-bola-4f4g</guid>
      <description>&lt;p&gt;Being a full-stack developer for quite some time, I have been consistently upgrading my full-stack knowledge by learning new technologies and features, along with how to implement them in a secure way.&lt;/p&gt;

&lt;h2&gt;
  
  
  What are WebSockets?
&lt;/h2&gt;

&lt;p&gt;WebSockets provide a full-duplex, persistent communication channel between the client and the server, enabling real-time data exchange without repeatedly creating new HTTP requests. They are widely used in applications such as chat systems, live notifications, collaborative platforms, and online gaming where low-latency communication is essential.&lt;/p&gt;

&lt;h2&gt;
  
  
  Implementing a Customer Support Chat System
&lt;/h2&gt;

&lt;p&gt;This time, I learned and implemented WebSockets for a customer service chat system, and I used the concept of a &lt;strong&gt;Chat Policy&lt;/strong&gt; for blocking customer-to-customer chats, which is against the policy of a customer service chat system where only admins and agents are allowed to be texted.&lt;/p&gt;

&lt;p&gt;On top of this, I learned how to implement a &lt;strong&gt;Chat Policy Service&lt;/strong&gt;, a completely distinct service with its own database queries and validations, and then integrate it into the message-handling events. You can create your own chat policy based on a specific database schema according to your application's requirements.&lt;/p&gt;

&lt;h2&gt;
  
  
  Project Architecture
&lt;/h2&gt;

&lt;p&gt;The overall folder structure of the chat system was organized by separating the socket initialization, socket events, services, middleware, authentication, and utilities, making the architecture modular and easier to maintain.&lt;/p&gt;

&lt;p&gt;The message handling logic remained inside dedicated event handlers, while business logic such as Chat Policy validation was delegated to its own service, following the principle of &lt;strong&gt;Separation of Concerns (SoC)&lt;/strong&gt;.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Example Folder Structure&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;
&lt;/blockquote&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;src/
├── socket/
│   ├── initSocket.ts
│   ├── onlineUsers.ts
│   ├── events/
│   │   ├── messageHandler.ts
│   │   └── disconnectHandler.ts
│   └── middleware/
│       └── socketAuth.ts
├── services/
│   ├── chatPolicy.service.ts
│   └── message.service.ts
├── models/
├── routes/
├── types/
├── utils/
└── server.ts
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Implementing Rate Limiting
&lt;/h2&gt;

&lt;p&gt;Along with this, I also came to understand the importance of rate limiting while sending text messages, so I learned to implement rate limiting using JavaScript's &lt;code&gt;Map&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;One thing that could be useful for your knowledge is creating a single instance of the service and exporting it. This allows all event handlers to use the same &lt;code&gt;Map&lt;/code&gt; across requests; otherwise, the counts and user information would not remain synchronized because each new instance would maintain its own separate memory.&lt;/p&gt;

&lt;p&gt;This approach works well when running a single server instance and is unlikely to restart or crash frequently. However, because &lt;code&gt;Map&lt;/code&gt; stores data only in memory, it is not persistent and does not work across multiple server instances. A more professional and production-standard solution is &lt;strong&gt;Redis&lt;/strong&gt;, which provides centralized and persistent storage shared among all application instances.&lt;/p&gt;

&lt;h3&gt;
  
  
  Map-Based Rate Limiter
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight typescript"&gt;&lt;code&gt;&lt;span class="k"&gt;import&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;UserLimit&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;from&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;../types/rateLimit.types.ts&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="kd"&gt;class&lt;/span&gt; &lt;span class="nc"&gt;RateLimiter&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;

    &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="nx"&gt;users&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nb"&gt;Map&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="kr"&gt;string&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;UserLimit&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;

    &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;readonly&lt;/span&gt; &lt;span class="nx"&gt;MAX_MESSAGES&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nc"&gt;Number&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;process&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;env&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;RATE_LIMIT_MESSAGES&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;readonly&lt;/span&gt; &lt;span class="nx"&gt;WINDOW_MS&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nc"&gt;Number&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;process&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;env&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;RATE_LIMIT_WINDOW&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="mi"&gt;1000&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

    &lt;span class="k"&gt;public&lt;/span&gt; &lt;span class="nf"&gt;canSend&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;username&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="kr"&gt;string&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt; &lt;span class="nx"&gt;boolean&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;now&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Date&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;now&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
        &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;user&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;this&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;users&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;username&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

        &lt;span class="k"&gt;if &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="nx"&gt;user&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="k"&gt;this&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;users&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;set&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;username&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="na"&gt;count&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                &lt;span class="na"&gt;windowStart&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;now&lt;/span&gt;
            &lt;span class="p"&gt;});&lt;/span&gt;
            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;

        &lt;span class="k"&gt;if &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;now&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt; &lt;span class="nx"&gt;user&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;windowStart&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="k"&gt;this&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;WINDOW_MS&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nx"&gt;user&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;count&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="nx"&gt;user&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;windowStart&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;now&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;

        &lt;span class="k"&gt;if &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;user&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;count&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="k"&gt;this&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;MAX_MESSAGES&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;

        &lt;span class="nx"&gt;user&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;count&lt;/span&gt;&lt;span class="o"&gt;++&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="k"&gt;export&lt;/span&gt; &lt;span class="k"&gt;default&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;RateLimiter&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Preventing Broken Object Level Authorization (BOLA)
&lt;/h2&gt;

&lt;p&gt;In addition to these security standards, one more important thing that I implemented was preventing the flaw of &lt;strong&gt;Broken Object Level Authorization (BOLA)&lt;/strong&gt;, which is one of the most critical API security vulnerabilities.&lt;/p&gt;

&lt;p&gt;BOLA occurs when an application trusts object identifiers or user information received from the client without verifying whether the authenticated user is actually authorized to access or modify those resources. A secure implementation should never trust identifiers such as usernames or user IDs coming directly from the frontend.&lt;/p&gt;

&lt;p&gt;While implementing the chat system, I learned to extract the authenticated user's ID and username directly from the verified authentication token instead of accepting them from the client payload. This ensures that every authorization decision is based on the identity established by the server after token verification, preventing malicious users from impersonating other users simply by modifying request data.&lt;/p&gt;

&lt;p&gt;By performing authorization checks on the server and validating permissions before processing chat events, the system effectively mitigates the risk of BOLA and enforces secure access control throughout the messaging workflow.&lt;/p&gt;

&lt;h2&gt;
  
  
  Key Takeaways
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Learned to build real-time communication using &lt;strong&gt;WebSockets&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Implemented a dedicated &lt;strong&gt;Chat Policy Service&lt;/strong&gt; for authorization rules.&lt;/li&gt;
&lt;li&gt;Structured the application using &lt;strong&gt;Separation of Concerns (SoC)&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Implemented &lt;strong&gt;Map-based rate limiting&lt;/strong&gt; and understood its limitations.&lt;/li&gt;
&lt;li&gt;Learned why &lt;strong&gt;Redis&lt;/strong&gt; is the production-standard solution for distributed rate limiting.&lt;/li&gt;
&lt;li&gt;Prevented &lt;strong&gt;Broken Object Level Authorization (BOLA)&lt;/strong&gt; by extracting authenticated user information from verified tokens instead of trusting client-provided data.&lt;/li&gt;
&lt;li&gt;Improved my understanding of secure backend architecture and real-time application development.&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>websocket</category>
      <category>cybersecurity</category>
      <category>node</category>
      <category>typescript</category>
    </item>
    <item>
      <title>How to Recover Lost Email IDs, Usernames, or Account Info Using Chrome/Browser Dev Tools</title>
      <dc:creator>Hassam Fathe Muhammad</dc:creator>
      <pubDate>Tue, 16 Jun 2026 17:28:12 +0000</pubDate>
      <link>https://dev.to/hassamdev/how-to-recover-lost-email-ids-usernames-or-account-info-using-chromebrowser-dev-tools-55n9</link>
      <guid>https://dev.to/hassamdev/how-to-recover-lost-email-ids-usernames-or-account-info-using-chromebrowser-dev-tools-55n9</guid>
      <description>&lt;p&gt;Mostly, if someone forgets account information, it is usually the password, and less commonly the username or email. But sometimes this can happen to many people working in tech due to handling multiple versatile accounts across different websites for relatively specific work.&lt;/p&gt;

&lt;p&gt;For example, on a hosting platform or database platform, one can have two accounts — one for personal experiments and one for production or professional work.&lt;/p&gt;

&lt;p&gt;In my case, I similarly had two accounts on a platform, and the Gmail ID used for one of them was very rarely used and not very active, due to which I forgot it completely. I also had no Google session logged in through which I could get the idea of the Gmail ID.&lt;/p&gt;

&lt;p&gt;After a long time, the platform refreshed its session and required a new login, with no account suggestions available. Now I was trapped with no idea of the Gmail ID.&lt;/p&gt;

&lt;p&gt;Neither the CLI of that platform was giving me my Gmail ID, nor any other command, etc. Since the email was the main identifier, the CLI was not revealing it. This could be due to several reasons:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Either it had no such function,&lt;/li&gt;
&lt;li&gt;It was never required before,&lt;/li&gt;
&lt;li&gt;Or the command was never commonly used, making it difficult even for ChatGPT or other AI assistants to provide a solution.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;At this point, I used my development knowledge and anticipated that most web apps use cookies and browser storage to store user or session-related information.&lt;/p&gt;

&lt;p&gt;So, I went to the platform site, opened Inspect/Developer Tools, and checked:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Application → Cookies&lt;/li&gt;
&lt;li&gt;Local Storage&lt;/li&gt;
&lt;li&gt;Session Storage&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;There, I found the same Gmail ID that I had used on the platform, allowing me to proceed and regain control of the account.&lt;/p&gt;

&lt;p&gt;The purpose of sharing this troubleshooting method is to help contribute toward recovering lost account information using one's own device and one's own browser inspect tools.&lt;/p&gt;

&lt;p&gt;However, such techniques and knowledge should never be used to copy, steal, or misuse someone else's session or account information from their devices.&lt;/p&gt;

</description>
      <category>webdev</category>
      <category>devtools</category>
      <category>tips</category>
      <category>productivity</category>
    </item>
    <item>
      <title>[Boost]</title>
      <dc:creator>Hassam Fathe Muhammad</dc:creator>
      <pubDate>Fri, 15 May 2026 09:23:27 +0000</pubDate>
      <link>https://dev.to/hassamdev/-3pea</link>
      <guid>https://dev.to/hassamdev/-3pea</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/hassamdev/beyond-crud-building-scalable-backends-with-work-queues-and-job-processing-n41" class="crayons-story__hidden-navigation-link"&gt;Beyond CRUD: Building Scalable Backends with Work Queues and Job Processing&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/hassamdev" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1806185%2Fe33362af-9a2c-4341-9915-76889ff7c1fa.jpg" alt="hassamdev profile" class="crayons-avatar__image" width="800" height="970"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/hassamdev" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Hassam Fathe Muhammad
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Hassam Fathe Muhammad
                
              
              &lt;div id="story-author-preview-content-3671344" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/hassamdev" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1806185%2Fe33362af-9a2c-4341-9915-76889ff7c1fa.jpg" class="crayons-avatar__image" alt="" width="800" height="970"&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Hassam Fathe Muhammad&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/hassamdev/beyond-crud-building-scalable-backends-with-work-queues-and-job-processing-n41" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;May 14&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/hassamdev/beyond-crud-building-scalable-backends-with-work-queues-and-job-processing-n41" id="article-link-3671344"&gt;
          Beyond CRUD: Building Scalable Backends with Work Queues and Job Processing
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/backend"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;backend&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/systemdesign"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;systemdesign&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/node"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;node&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/bullmq"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;bullmq&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
            &lt;a href="https://dev.to/hassamdev/beyond-crud-building-scalable-backends-with-work-queues-and-job-processing-n41#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              &lt;span class="hidden s:inline"&gt;Add&amp;nbsp;Comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            4 min read
          &lt;/small&gt;
            
              &lt;span class="bm-initial crayons-icon c-btn__icon"&gt;
                

              &lt;/span&gt;
              &lt;span class="bm-success crayons-icon c-btn__icon"&gt;
                

              &lt;/span&gt;
            
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>4 Tiny Frontend Mistakes Quietly Killing Your App Performance</title>
      <dc:creator>Hassam Fathe Muhammad</dc:creator>
      <pubDate>Thu, 14 May 2026 19:09:25 +0000</pubDate>
      <link>https://dev.to/hassamdev/-518j</link>
      <guid>https://dev.to/hassamdev/-518j</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/sylwia-lask/4-tiny-mistakes-that-secretly-destroy-app-performance-3cgo" class="crayons-story__hidden-navigation-link"&gt;4 Tiny Mistakes That Secretly Destroy App Performance&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
      &lt;a href="https://dev.to/sylwia-lask/4-tiny-mistakes-that-secretly-destroy-app-performance-3cgo" class="crayons-article__context-note crayons-article__context-note__feed"&gt;&lt;p&gt;Real-world cases and energy-saving impacts&lt;/p&gt;

&lt;/a&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/sylwia-lask" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3535771%2Fe22860d5-274b-43c9-819b-56b162e5bd5a.jpeg" alt="sylwia-lask profile" class="crayons-avatar__image" width="800" height="806"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/sylwia-lask" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Sylwia Laskowska
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Sylwia Laskowska
                
              
              &lt;div id="story-author-preview-content-3666204" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/sylwia-lask" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3535771%2Fe22860d5-274b-43c9-819b-56b162e5bd5a.jpeg" class="crayons-avatar__image" alt="" width="800" height="806"&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Sylwia Laskowska&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/sylwia-lask/4-tiny-mistakes-that-secretly-destroy-app-performance-3cgo" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;May 14&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/sylwia-lask/4-tiny-mistakes-that-secretly-destroy-app-performance-3cgo" id="article-link-3666204"&gt;
          4 Tiny Mistakes That Secretly Destroy App Performance
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/javascript"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;javascript&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/angular"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;angular&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/react"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;react&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/frontend"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;frontend&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/sylwia-lask/4-tiny-mistakes-that-secretly-destroy-app-performance-3cgo" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/exploding-head-daceb38d627e6ae9b730f36a1e390fca556a4289d5a41abb2c35068ad3e2c4b5.svg" width="24" height="24"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/fire-f60e7a582391810302117f987b22a8ef04a2fe0df7e3258a5f49332df1cec71e.svg" width="24" height="24"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="24" height="24"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;112&lt;span class="hidden s:inline"&gt;&amp;nbsp;reactions&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/sylwia-lask/4-tiny-mistakes-that-secretly-destroy-app-performance-3cgo#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              56&lt;span class="hidden s:inline"&gt;&amp;nbsp;comments&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            6 min read
          &lt;/small&gt;
            
              &lt;span class="bm-initial crayons-icon c-btn__icon"&gt;
                

              &lt;/span&gt;
              &lt;span class="bm-success crayons-icon c-btn__icon"&gt;
                

              &lt;/span&gt;
            
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>Beyond CRUD: Building Scalable Backends with Work Queues and Job Processing</title>
      <dc:creator>Hassam Fathe Muhammad</dc:creator>
      <pubDate>Thu, 14 May 2026 18:27:37 +0000</pubDate>
      <link>https://dev.to/hassamdev/beyond-crud-building-scalable-backends-with-work-queues-and-job-processing-n41</link>
      <guid>https://dev.to/hassamdev/beyond-crud-building-scalable-backends-with-work-queues-and-job-processing-n41</guid>
      <description>&lt;p&gt;Apart from CRUD work in backend, there is a lot more to learn and implement in your projects to allow scalable, powerful, and reliable system design. As most of us full-stack and backend developers work with APIs for user-oriented operations which are being triggered from frontend by end users in their various tasks, and then the response of those APIs for that task informs user and drives their work forward, navigates them to further pages, fetches them the required info, and provides them with services.&lt;/p&gt;

&lt;p&gt;But not all types of workflows can be given to a designed API and then accomplished in short time with that one single API — it can be, but not on user's waiting. The user expects the web app or app response for his or her simple triggered task. But it is the backend which knows how many actions and tasks must be performed and in which order.&lt;/p&gt;




&lt;h2&gt;
  
  
  The Solution: Work Queues
&lt;/h2&gt;

&lt;p&gt;For this we use &lt;strong&gt;Work Queues&lt;/strong&gt; and give the work to the workers, whereas a success or work-in-progress response is being sent to the user — allowing it to move along rather than waiting for the whole set of backend operations.&lt;/p&gt;




&lt;h2&gt;
  
  
  My Implementation Journey
&lt;/h2&gt;

&lt;p&gt;For explanation and demonstration, I will be implementing this concept in one of my projects which involves a set of tasks. As I also worked with Redux for state management in my 'Nur Fashions' e-commerce web app, I decided further upgrade of this project with queues &amp;amp; jobs would be better for learning and productive for this project, adding value to it.&lt;/p&gt;




&lt;h2&gt;
  
  
  Technology Stack
&lt;/h2&gt;

&lt;p&gt;The module/library I used for this was &lt;strong&gt;BullMQ&lt;/strong&gt; and the storage and execution engine used was &lt;strong&gt;Redis&lt;/strong&gt;, as BullMQ is made on top of Redis. So I used Docker to run my Redis image and allow connection from localhost.&lt;/p&gt;




&lt;h2&gt;
  
  
  Use Case: Order Processing
&lt;/h2&gt;

&lt;p&gt;Now in my Nur Fashions e-com web app, I selected the order processing aspect. As the backend was already saving order entry to the database and giving success response, now as we discussed, we did not need to overwhelm this API and add other required tasks into it such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Update Inventory for selected ordered items&lt;/li&gt;
&lt;li&gt;Send Email to customer (user)&lt;/li&gt;
&lt;li&gt;Generate Invoice&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;which I now gave to the workers of the queue.&lt;/p&gt;




&lt;h2&gt;
  
  
  System Architecture &amp;amp; Design
&lt;/h2&gt;

&lt;p&gt;Now as I always try to design systems for scalability and modular for cleaner and helpful abstraction, so I made up:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Queue Config File&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Job Addition From Controller Code:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;orderQueue&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;add&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;processOrder&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="na"&gt;orderId&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;orderData&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;orderId&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="na"&gt;orderEmail&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;orderDetails&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;customer&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;email&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="na"&gt;items&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;orderDetails&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;items&lt;/span&gt;
&lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="na"&gt;attempts&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="na"&gt;backoff&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="na"&gt;type&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;exponential&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="na"&gt;delay&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;5000&lt;/span&gt;
    &lt;span class="p"&gt;},&lt;/span&gt;
    &lt;span class="na"&gt;removeOnComplete&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;100&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="na"&gt;removeOnFail&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt; 
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Worker Task Handling File&lt;/strong&gt; along with limiter and retry logic&lt;/p&gt;




&lt;h2&gt;
  
  
  Running Workers Separately
&lt;/h2&gt;

&lt;p&gt;Now it was observed and learned by me that workers and queues must be started separately. So as this was a crucial part of server/backend, I used a module called &lt;strong&gt;'concurrently'&lt;/strong&gt; which executes a list of commands at the same time.&lt;/p&gt;

&lt;p&gt;So I made up one index.ts main worker file which was importing Order Worker File, allowing to start different workers in future.&lt;/p&gt;




&lt;h2&gt;
  
  
  Handling Job Failures: The Critical Part
&lt;/h2&gt;

&lt;p&gt;This is where I got this concern of what if any task/job fails. So I got confronted by different approaches in which the more obvious all along was to have a vast and detailed DB schema for order table/collection. So I made up properties/attributes such as:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="nx"&gt;inventoryProcessed&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;Boolean&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="nx"&gt;inventoryProcessedAt&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;Date&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="nx"&gt;emailSent&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;Boolean&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="nx"&gt;emailSentAt&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;Date&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="nx"&gt;invoiceGenerated&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;Boolean&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="nx"&gt;invoiceGeneratedAt&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;Date&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="nx"&gt;processing&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nl"&gt;inventoryError&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;String&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;inventoryLastAttempt&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;Date&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;emailError&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;String&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;emailLastAttempt&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;Date&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;invoiceError&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;String&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;invoiceLastAttempt&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;Date&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt; 
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  Dual Storage Strategy
&lt;/h2&gt;

&lt;p&gt;This allowed me to update info for dead jobs handling and debugging. Along with this, I used &lt;strong&gt;Redis&lt;/strong&gt; to store flags based on completion/failure of jobs:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="k"&gt;try&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;inventoryProcessed&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;redis&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;hget&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;`order:&lt;/span&gt;&lt;span class="p"&gt;${&lt;/span&gt;&lt;span class="nx"&gt;orderId&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;:flags`&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;inventoryProcessed&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

    &lt;span class="k"&gt;if &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;inventoryProcessed&lt;/span&gt; &lt;span class="o"&gt;!==&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;1&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;Updating Inventory: &lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;orderId&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;InventoryController&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;updateInventoryPostOrder&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;items&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

        &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nb"&gt;Promise&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;all&lt;/span&gt;&lt;span class="p"&gt;([&lt;/span&gt;
            &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;redis&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;hset&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;`order:&lt;/span&gt;&lt;span class="p"&gt;${&lt;/span&gt;&lt;span class="nx"&gt;orderId&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;:flags`&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;inventoryProcessed&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;1&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
            &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;order&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;updateOne&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;&lt;span class="nx"&gt;orderId&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="na"&gt;inventoryProcessed&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; 
                &lt;span class="na"&gt;inventoryProcessedAt&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;Date&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
            &lt;span class="p"&gt;})&lt;/span&gt;
        &lt;span class="p"&gt;]);&lt;/span&gt;     
    &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;Inventory Already Processed, &lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;orderId&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;catch &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;any&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nx"&gt;errors&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;inventory&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;message&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;`Error While Updating Inventory, &lt;/span&gt;&lt;span class="p"&gt;${&lt;/span&gt;&lt;span class="nx"&gt;orderId&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;, `&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;message&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

    &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;order&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;updateOne&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;&lt;span class="nx"&gt;orderId&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;processing.inventoryError&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;message&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;processing.inventoryLastAttempt&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;Date&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;As in the same way for other tasks in this order process. &lt;/p&gt;

&lt;p&gt;Then I also configured the &lt;strong&gt;limiter&lt;/strong&gt; as down below and did exception/error handling along notifying the admin for failed jobs:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nl"&gt;connection&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="na"&gt;host&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;127.0.0.1&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="na"&gt;port&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;6379&lt;/span&gt; &lt;span class="p"&gt;},&lt;/span&gt;
    &lt;span class="nx"&gt;limiter&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nl"&gt;max&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;10&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="nx"&gt;duration&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;10000&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="p"&gt;},&lt;/span&gt;
    &lt;span class="nx"&gt;concurrency&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;5&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="c1"&gt;///////////&lt;/span&gt;

&lt;span class="nx"&gt;worker&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;on&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;completed&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;job&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;`Job &lt;/span&gt;&lt;span class="p"&gt;${&lt;/span&gt;&lt;span class="nx"&gt;job&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;id&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="s2"&gt; completed Successfully`&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;

&lt;span class="nx"&gt;worker&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;on&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;failed&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;async &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;job&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;error&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;`Job &lt;/span&gt;&lt;span class="p"&gt;${&lt;/span&gt;&lt;span class="nx"&gt;job&lt;/span&gt;&lt;span class="p"&gt;?.&lt;/span&gt;&lt;span class="nx"&gt;id&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="s2"&gt; failed, `&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;message&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

    &lt;span class="k"&gt;if &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;job&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nx"&gt;job&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;attemptsMade&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;=&lt;/span&gt; &lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;AlertController&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;sendAlertToAdmin&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
            &lt;span class="na"&gt;orderId&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;job&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;data&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;orderId&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="na"&gt;error&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;message&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="na"&gt;attempts&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;job&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;attemptsMade&lt;/span&gt;
        &lt;span class="p"&gt;});&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;

&lt;span class="nx"&gt;worker&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;on&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;error&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;error&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;Worker Error, &lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;Now this is how I learned and implemented worker queues using BullMQ to add scalable, value, and reliable features to my backend, upgrading my backend skill stack and keeping users moving along on the frontend.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Real engineers:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Design for scale from the start&lt;/li&gt;
&lt;li&gt;Handle failures gracefully&lt;/li&gt;
&lt;li&gt;Keep users informed without making them wait&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>backend</category>
      <category>systemdesign</category>
      <category>node</category>
      <category>bullmq</category>
    </item>
    <item>
      <title>[Boost]</title>
      <dc:creator>Hassam Fathe Muhammad</dc:creator>
      <pubDate>Sat, 28 Mar 2026 09:27:44 +0000</pubDate>
      <link>https://dev.to/hassamdev/-273h</link>
      <guid>https://dev.to/hassamdev/-273h</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/klement_gunndu/vibe-coding-got-you-started-these-5-skills-keep-you-employed-23pn" class="crayons-story__hidden-navigation-link"&gt;Vibe Coding Got You Started. These 5 Skills Keep You Employed.&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/klement_gunndu" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3786236%2Fe2629efd-63ba-4d1b-83d8-b55db5d86b58.jpeg" alt="klement_gunndu profile" class="crayons-avatar__image" width="800" height="702"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/klement_gunndu" class="crayons-story__secondary fw-medium m:hidden"&gt;
              klement Gunndu
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                klement Gunndu
                
              
              &lt;div id="story-author-preview-content-3402293" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/klement_gunndu" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3786236%2Fe2629efd-63ba-4d1b-83d8-b55db5d86b58.jpeg" class="crayons-avatar__image" alt="" width="800" height="702"&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;klement Gunndu&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/klement_gunndu/vibe-coding-got-you-started-these-5-skills-keep-you-employed-23pn" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Mar 25&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/klement_gunndu/vibe-coding-got-you-started-these-5-skills-keep-you-employed-23pn" id="article-link-3402293"&gt;
          Vibe Coding Got You Started. These 5 Skills Keep You Employed.
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/ai"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;ai&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/beginners"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;beginners&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/career"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;career&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/programming"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;programming&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/klement_gunndu/vibe-coding-got-you-started-these-5-skills-keep-you-employed-23pn" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/raised-hands-74b2099fd66a39f2d7eed9305ee0f4553df0eb7b4f11b01b6b1b499973048fe5.svg" width="24" height="24"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/exploding-head-daceb38d627e6ae9b730f36a1e390fca556a4289d5a41abb2c35068ad3e2c4b5.svg" width="24" height="24"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="24" height="24"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;33&lt;span class="hidden s:inline"&gt;&amp;nbsp;reactions&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/klement_gunndu/vibe-coding-got-you-started-these-5-skills-keep-you-employed-23pn#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              16&lt;span class="hidden s:inline"&gt;&amp;nbsp;comments&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            6 min read
          &lt;/small&gt;
            
              &lt;span class="bm-initial crayons-icon c-btn__icon"&gt;
                

              &lt;/span&gt;
              &lt;span class="bm-success crayons-icon c-btn__icon"&gt;
                

              &lt;/span&gt;
            
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
      <category>ai</category>
      <category>beginners</category>
      <category>career</category>
      <category>programming</category>
    </item>
    <item>
      <title>Just Did Work On OWASP A05</title>
      <dc:creator>Hassam Fathe Muhammad</dc:creator>
      <pubDate>Fri, 27 Mar 2026 15:23:12 +0000</pubDate>
      <link>https://dev.to/hassamdev/-2el5</link>
      <guid>https://dev.to/hassamdev/-2el5</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/hassamdev/owasp-top-10-a05-security-misconfiguration-remediation-perspective-2d30" class="crayons-story__hidden-navigation-link"&gt;OWASP Top 10 – A05: Security Misconfiguration (Remediation Perspective)&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/hassamdev" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1806185%2Fe33362af-9a2c-4341-9915-76889ff7c1fa.jpg" alt="hassamdev profile" class="crayons-avatar__image" width="800" height="970"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/hassamdev" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Hassam Fathe Muhammad
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Hassam Fathe Muhammad
                
              
              &lt;div id="story-author-preview-content-3415783" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/hassamdev" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1806185%2Fe33362af-9a2c-4341-9915-76889ff7c1fa.jpg" class="crayons-avatar__image" alt="" width="800" height="970"&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Hassam Fathe Muhammad&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/hassamdev/owasp-top-10-a05-security-misconfiguration-remediation-perspective-2d30" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Mar 27&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/hassamdev/owasp-top-10-a05-security-misconfiguration-remediation-perspective-2d30" id="article-link-3415783"&gt;
          OWASP Top 10 – A05: Security Misconfiguration (Remediation Perspective)
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/security"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;security&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/systemdesign"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;systemdesign&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/owasp"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;owasp&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/hassamdev/owasp-top-10-a05-security-misconfiguration-remediation-perspective-2d30" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/fire-f60e7a582391810302117f987b22a8ef04a2fe0df7e3258a5f49332df1cec71e.svg" width="24" height="24"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="24" height="24"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;3&lt;span class="hidden s:inline"&gt;&amp;nbsp;reactions&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/hassamdev/owasp-top-10-a05-security-misconfiguration-remediation-perspective-2d30#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              &lt;span class="hidden s:inline"&gt;Add&amp;nbsp;Comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            3 min read
          &lt;/small&gt;
            
              &lt;span class="bm-initial crayons-icon c-btn__icon"&gt;
                

              &lt;/span&gt;
              &lt;span class="bm-success crayons-icon c-btn__icon"&gt;
                

              &lt;/span&gt;
            
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
      <category>security</category>
      <category>systemdesign</category>
      <category>owasp</category>
    </item>
    <item>
      <title>OWASP Top 10 – A05: Security Misconfiguration (Remediation Perspective)</title>
      <dc:creator>Hassam Fathe Muhammad</dc:creator>
      <pubDate>Fri, 27 Mar 2026 15:22:40 +0000</pubDate>
      <link>https://dev.to/hassamdev/owasp-top-10-a05-security-misconfiguration-remediation-perspective-2d30</link>
      <guid>https://dev.to/hassamdev/owasp-top-10-a05-security-misconfiguration-remediation-perspective-2d30</guid>
      <description>&lt;p&gt;As I have been working with OWASP Top 10, so far I have studied A01 to A04 and performed remediations according to them on my projects, so I can have an idea of security and standard testing of my web apps. In this article, I would like to tell you about my work regarding A05, which is &lt;strong&gt;Security Misconfiguration&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;t is observed by me that many of the aspects addressed in one OWASP category can also be addressed in more than one category. So this is more about discipline while developing a web app.&lt;/p&gt;

&lt;p&gt;In my work on OWASP A05, I performed the following remediations and improvements:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; As some aspects are also addressed in more than one OWASP category, my work is more likely inclined toward one specific category in this article.&lt;/p&gt;




&lt;h2&gt;
  
  
  Environment Configuration
&lt;/h2&gt;

&lt;p&gt;One of the aspects that many beginner developers miss out on—and exhibit work-shyness in—is not preparing separate environments for:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Development (Project Making)&lt;/li&gt;
&lt;li&gt;Local (Running on a local closed network)&lt;/li&gt;
&lt;li&gt;Production (Deploying the project as delivered and ready to meet the internet)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This configuration can be done by preparing .env files accordingly and editing them for the type of project start.&lt;/p&gt;

&lt;p&gt;**For example: **It is best and advised to have this variable:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight conf"&gt;&lt;code&gt;&lt;span class="n"&gt;NODE_ENV&lt;/span&gt;=&lt;span class="n"&gt;production&lt;/span&gt;

&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The variable value can be changed according to the project environment like "dev" for development, "local" for local, and "prod" for production.&lt;/p&gt;

&lt;p&gt;This allows necessary condition checks and flag triggering such as:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="k"&gt;if &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;process&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;env&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;NODE_ENV&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;production&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="nx"&gt;app&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;set&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;trust proxy&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This allows IP address logging and other rate-limiting and security methods to be applied.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; Proxy must be trusted with this flag only if you are using NGINX or another trusted reverse proxy like Cloudflare or reputed hosting services.&lt;/p&gt;




&lt;h2&gt;
  
  
  Secure HTTP Headers
&lt;/h2&gt;

&lt;p&gt;Another security misconfiguration that must be handled is the use of &lt;strong&gt;Helmet&lt;/strong&gt; for securing HTTP headers.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="k"&gt;import&lt;/span&gt; &lt;span class="nx"&gt;helmet&lt;/span&gt; &lt;span class="k"&gt;from&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;helmet&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="nx"&gt;app&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;use&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nf"&gt;helmet&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This adds:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Content-Security-Policy&lt;/li&gt;
&lt;li&gt;XSS Protection&lt;/li&gt;
&lt;li&gt;Frameguard&lt;/li&gt;
&lt;li&gt;HSTS&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  CORS Configuration
&lt;/h2&gt;

&lt;p&gt;Another important configuration is CORS:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="nx"&gt;app&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;use&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nf"&gt;cors&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
  &lt;span class="na"&gt;origin&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;https://yourfrontend.com&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;
  &lt;span class="na"&gt;credentials&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;
&lt;span class="p"&gt;}));&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;One should regularly identify their domains and use the correct URLs in their CORS configuration.&lt;/p&gt;




&lt;h2&gt;
  
  
  Hide Sensitive Errors
&lt;/h2&gt;

&lt;p&gt;Many developers forward backend errors to the frontend for quick debugging, like:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;status&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;500&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nf"&gt;json&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt; &lt;span class="na"&gt;error&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;err&lt;/span&gt; &lt;span class="p"&gt;});&lt;/span&gt;

&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This is not advised, as it may expose backend structure, repositories, or system limitations.&lt;/p&gt;

&lt;p&gt;Instead, use standard messages such as:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;status&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;500&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nf"&gt;json&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt; &lt;span class="na"&gt;message&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;Internal Server Error&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="p"&gt;});&lt;/span&gt;

&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For debugging, use server logs:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="k"&gt;try&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="c1"&gt;// Logic&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;catch &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;error&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;Error While Processing In (Endpoint)&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;status&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;500&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nf"&gt;json&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt; &lt;span class="na"&gt;message&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;Internal Server Error&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  Disable Stack Traces &amp;amp; Info Leaks
&lt;/h2&gt;

&lt;p&gt;Information about backend resources matters a lot. It allows attackers to guess weaknesses and evaluate your servers.&lt;/p&gt;

&lt;p&gt;We can use:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="nx"&gt;app&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;disable&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;x-powered-by&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This hides:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;X-Powered-By: Express&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Enforce HTTPS
&lt;/h2&gt;

&lt;p&gt;When using hosting services, they often handle HTTPS automatically.&lt;/p&gt;

&lt;p&gt;But when deploying manually using a reverse proxy like &lt;strong&gt;NGINX&lt;/strong&gt;, ensure:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;NGINX + Certbot setup&lt;/li&gt;
&lt;li&gt;Redirect HTTP → HTTPS&lt;/li&gt;
&lt;li&gt;Install SSL certificate&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Usually, this is part of NGINX deployment.&lt;/p&gt;




&lt;h2&gt;
  
  
  Secure Cookies
&lt;/h2&gt;

&lt;p&gt;While setting cookies from the backend, ensure the following:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;cookie&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;token&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;token&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="na"&gt;httpOnly&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;secure&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;sameSite&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;strict&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;

&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  Remove Default Credentials
&lt;/h2&gt;

&lt;p&gt;During development, many developers use default credentials for quick testing.&lt;/p&gt;

&lt;p&gt;Removing these from the database is very important.&lt;/p&gt;

&lt;p&gt;If missed, attackers might try:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Username: admin&lt;/li&gt;
&lt;li&gt;Password: admin&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;and gain admin access.&lt;/p&gt;




&lt;h2&gt;
  
  
  Advanced Insight
&lt;/h2&gt;

&lt;p&gt;Security Misconfiguration is &lt;strong&gt;NOT a bug&lt;/strong&gt;. It’s a &lt;strong&gt;discipline problem.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Most developers:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Focus on features&lt;/li&gt;
&lt;li&gt;Ignore deployment &amp;amp; configurations&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Real engineers:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Secure systems at both infrastructure and application levels&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>systemdesign</category>
      <category>owasp</category>
    </item>
    <item>
      <title>Redux vs React Context: A Practical Perspective from a Real Project</title>
      <dc:creator>Hassam Fathe Muhammad</dc:creator>
      <pubDate>Wed, 28 Jan 2026 16:39:55 +0000</pubDate>
      <link>https://dev.to/hassamdev/redux-vs-react-context-a-practical-perspective-from-a-real-project-1o0a</link>
      <guid>https://dev.to/hassamdev/redux-vs-react-context-a-practical-perspective-from-a-real-project-1o0a</guid>
      <description>&lt;p&gt;Back then, I started using &lt;strong&gt;React Context&lt;/strong&gt; in my web apps mainly for &lt;strong&gt;auth&lt;/strong&gt; and &lt;strong&gt;session-related info/status.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The idea of Context is simple: it is created for the app (its components) so that &lt;strong&gt;prop drilling can be avoided&lt;/strong&gt;, and the state can be easily accessed by the components that actually need it—while ensuring proper updates and usage of state data.&lt;/p&gt;

&lt;p&gt;The &lt;strong&gt;React Context API&lt;/strong&gt; (createContext, useContext, useState, etc.) worked well for me, and I’ve used it in many of my web apps &lt;strong&gt;(React + Next.js).&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;What I liked the most—and what I think many developers will find helpful—is how it &lt;strong&gt;eliminates prop drilling&lt;/strong&gt; and helps in understanding the layout structure when using a Context Provider. I became quite comfortable with React Context.&lt;/p&gt;

&lt;p&gt;But there is also another library designed for managing shared state and complexity: &lt;strong&gt;Redux.&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Enter Redux
&lt;/h2&gt;

&lt;p&gt;Using Redux requires understanding a few core concepts:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Store&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Slices&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reducers&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Actions&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The &lt;strong&gt;Store&lt;/strong&gt;, which is the global state container, is &lt;strong&gt;singular&lt;/strong&gt;—there is only one store in an app. Inside it, you have multiple &lt;strong&gt;slices&lt;/strong&gt;, where each slice represents a specific feature or concern and contains its &lt;strong&gt;state, reducers, and actions.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I’m not writing this article to teach Redux or deeply explore its internal structure. Instead, I’ll explain my thinking using an example from one of my projects.&lt;/p&gt;




&lt;h2&gt;
  
  
  A Real Project Example
&lt;/h2&gt;

&lt;p&gt;I have an &lt;strong&gt;e-commerce-based Next.js web app&lt;/strong&gt; called &lt;strong&gt;Nur Fashions.&lt;/strong&gt; It’s a template-nature, client-based project.&lt;/p&gt;

&lt;p&gt;In this project, I’m &lt;strong&gt;using React Context&lt;/strong&gt; for:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Authentication&lt;/li&gt;
&lt;li&gt;Cart management&lt;/li&gt;
&lt;li&gt;Location (for currency, etc.)
From my experience, &lt;strong&gt;Context API is completely fine for these use cases.&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Why?&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;No complex backend involvement&lt;/li&gt;
&lt;li&gt;No heavy backend syncing&lt;/li&gt;
&lt;li&gt;No asynchronous workflows&lt;/li&gt;
&lt;li&gt;Fewer uncertain or branching operations&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;So for these parts of the app, &lt;strong&gt;React Context is more than enough&lt;/strong&gt;—there is simply &lt;strong&gt;no need for Redux&lt;/strong&gt; here.&lt;/p&gt;




&lt;h2&gt;
  
  
  Where Redux Makes Sense
&lt;/h2&gt;

&lt;p&gt;However, one important process in this app is the &lt;strong&gt;ordering flow after cart checkout.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This process needs to be handled very carefully:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;It involves &lt;strong&gt;asynchronous operations&lt;/strong&gt; with the backend&lt;/li&gt;
&lt;li&gt;It requires &lt;strong&gt;clearly defined and strongly typed states&lt;/strong&gt; (loading, success, failure, etc.)&lt;/li&gt;
&lt;li&gt;It has the potential to &lt;strong&gt;grow in complexity and scalability&lt;/strong&gt;, with more backend syncing and business logic added over time&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For this reason, using &lt;strong&gt;Redux&lt;/strong&gt; here felt both &lt;strong&gt;reasonable and professional.&lt;/strong&gt; So I set up Redux (store + slice) and wrapped it with a provider in the layout.&lt;/p&gt;




&lt;h2&gt;
  
  
  A Key Realization
&lt;/h2&gt;

&lt;p&gt;While working on this, I came across a very important professional insight:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Redux is NOT about lifetime. Redux is about complexity.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Before understanding this, I was more convinced of the idea that Redux should only be used for long-living context or global state. But now my perspective has changed.&lt;/p&gt;

&lt;p&gt;What truly matters is &lt;strong&gt;how complex and scalable the state logic is&lt;/strong&gt;, not how long the data lives.&lt;/p&gt;

&lt;p&gt;And that, for me, is the real distinction between &lt;strong&gt;React Context&lt;/strong&gt; and &lt;strong&gt;Redux&lt;/strong&gt;.&lt;/p&gt;

</description>
      <category>react</category>
      <category>redux</category>
      <category>contextapi</category>
      <category>nextjs</category>
    </item>
    <item>
      <title>OWASP Top 10 – A04: Insecure Design (Remediation Perspective)</title>
      <dc:creator>Hassam Fathe Muhammad</dc:creator>
      <pubDate>Wed, 28 Jan 2026 15:54:00 +0000</pubDate>
      <link>https://dev.to/hassamdev/owasp-top-10-a04-insecure-design-remediation-perspective-12pp</link>
      <guid>https://dev.to/hassamdev/owasp-top-10-a04-insecure-design-remediation-perspective-12pp</guid>
      <description>&lt;p&gt;As I have been trying to cover the &lt;strong&gt;OWASP Top 10&lt;/strong&gt; to make my &lt;strong&gt;full-stack development skills&lt;/strong&gt; more valuable, standardized, and aligned with the &lt;strong&gt;cybersecurity domain&lt;/strong&gt;, the topics I have already covered include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;A01 – Broken Access Control&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;A02 – Cryptographic Failures&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;A03 – Injection&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In this article, I will talk about &lt;strong&gt;A04 (Insecure Design)&lt;/strong&gt;, its remediation, and how it differs from &lt;strong&gt;A01&lt;/strong&gt; in some important ways.&lt;/p&gt;




&lt;h2&gt;
  
  
  What A04 (Insecure Design) Focuses On
&lt;/h2&gt;

&lt;p&gt;A04 focuses on the &lt;strong&gt;absence of proper logic and security mechanisms at the design and implementation level&lt;/strong&gt; of a web application or website, which ultimately makes it insecure.&lt;/p&gt;

&lt;p&gt;Some practices that commonly lead to &lt;strong&gt;Insecure Design&lt;/strong&gt; include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Trusting the &lt;strong&gt;client-side&lt;/strong&gt; too much&lt;/li&gt;
&lt;li&gt;Not designing &lt;strong&gt;APIs and gateways&lt;/strong&gt; according to &lt;strong&gt;server-issued protocols and rules&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Performing &lt;strong&gt;sensitive processing on the client side&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Fetching &lt;strong&gt;sensitive data on the frontend when it is not required&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Practical Handling of A04 in My Project
&lt;/h2&gt;

&lt;p&gt;In this article, I’ll explain some of the practices I eliminated to avoid &lt;strong&gt;A04 (Insecure Design)&lt;/strong&gt; issues in one of my projects, &lt;strong&gt;Alpha Connect Hub (now IoT Nerve).&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Handling A04 across the &lt;strong&gt;entire project and all modules&lt;/strong&gt; is my responsibility as a skilled full-stack developer to ensure that no cybersecurity issues are introduced due to weak design decisions.&lt;/p&gt;

&lt;p&gt;To keep this article focused and practical, I will explain A04 using a &lt;strong&gt;specific module example.&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Example Module: MQTT Broker Server Credentials
&lt;/h2&gt;

&lt;p&gt;This module is responsible for &lt;strong&gt;setting up credentials (username and password)&lt;/strong&gt; for the &lt;strong&gt;MQTT Authentication Service&lt;/strong&gt;, which is required to connect to the MQTT Broker.&lt;/p&gt;

&lt;h2&gt;
  
  
  Insecure Practices Eliminated
&lt;/h2&gt;

&lt;p&gt;One of the main vulnerabilities that must be rooted out in this module is:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Fetching the password on the frontend&lt;/strong&gt; (even in hashed form)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The involvement of &lt;strong&gt;passwords or authentication keys on the frontend&lt;/strong&gt; directly contributes to &lt;strong&gt;Insecure Design.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Another insecure practice that must not be allowed is:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Allowing the &lt;strong&gt;password-changing mechanism&lt;/strong&gt; to proceed &lt;strong&gt;without verifying the original (old) password&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Requiring the previous password ensures &lt;strong&gt;ownership verification&lt;/strong&gt; and keeps access control intact.&lt;/p&gt;




&lt;h2&gt;
  
  
  Route Protection &amp;amp; OWASP Categorization
&lt;/h2&gt;

&lt;p&gt;All routes used in this module are &lt;strong&gt;protected&lt;/strong&gt; and require a &lt;strong&gt;server-issued token&lt;/strong&gt;, enforced through middleware, before any real operation is performed.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Negligence in protecting such routes&lt;/strong&gt; falls under &lt;strong&gt;A01 – Broken Access Control&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;The absence of proper route design&lt;/strong&gt;, reasonable parameters, and a &lt;strong&gt;secure &amp;amp; safe output/result schema&lt;/strong&gt; falls under &lt;strong&gt;A04 – Insecure Design&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>systemdesign</category>
      <category>owasp</category>
    </item>
    <item>
      <title>From Internship to Enterprise Development: My Journey into MDM, EMM &amp; API Publishing</title>
      <dc:creator>Hassam Fathe Muhammad</dc:creator>
      <pubDate>Sat, 01 Nov 2025 16:08:30 +0000</pubDate>
      <link>https://dev.to/hassamdev/from-internship-to-enterprise-development-my-journey-into-mdm-emm-api-publishing-3327</link>
      <guid>https://dev.to/hassamdev/from-internship-to-enterprise-development-my-journey-into-mdm-emm-api-publishing-3327</guid>
      <description>&lt;h2&gt;
  
  
  🔒 Disclaimer / Notice
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;This article is purely based on learning, exploration, and research into &lt;strong&gt;MDM&lt;/strong&gt;, &lt;strong&gt;EMM&lt;/strong&gt;, and &lt;strong&gt;API publishing technologies&lt;/strong&gt; during my internship and personal projects.  &lt;/p&gt;

&lt;p&gt;No production-level deployments, enterprise bypassing, or unauthorized development for business gains were performed.  &lt;/p&gt;

&lt;p&gt;All experiments were done in local/demo environments and with educational intent.  &lt;/p&gt;

&lt;p&gt;The purpose of this write-up is to &lt;strong&gt;share knowledge&lt;/strong&gt; and &lt;strong&gt;document my journey&lt;/strong&gt;, not to promote or replicate enterprise deployments without proper authorization.  &lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  🏁 Starting Point: My Internship at Mercurial Minds
&lt;/h2&gt;

&lt;p&gt;During my internship at &lt;strong&gt;Mercurial Minds (M.M)&lt;/strong&gt;, I was placed in the &lt;strong&gt;Enterprise Mobility Management (EMM) / Mobile Device Management (MDM)&lt;/strong&gt; department.&lt;br&gt;&lt;br&gt;
At first, I wasn’t fully clear on what these systems were about — tools like &lt;em&gt;Samsung Knox&lt;/em&gt; and other enterprise EMM platforms felt overwhelming.  &lt;/p&gt;

&lt;p&gt;But gradually, I discovered that &lt;strong&gt;EMM/MDM isn’t just about managing devices — it’s a core product area that many leading software companies invest in.&lt;/strong&gt;  &lt;/p&gt;

&lt;p&gt;This was my first real exposure to &lt;strong&gt;enterprise-level technology&lt;/strong&gt;, beyond the world of small-scale software projects.  &lt;/p&gt;




&lt;h2&gt;
  
  
  🔍 Diving Deeper: From Confusion to Curiosity
&lt;/h2&gt;

&lt;p&gt;As I got hands-on experience with an &lt;strong&gt;EMM/MDM portal&lt;/strong&gt; on a demo server, my curiosity grew. With some research, I found that the portal was powered by the &lt;strong&gt;Entgra IoT Server&lt;/strong&gt;.  &lt;/p&gt;

&lt;p&gt;Instead of stopping there, I pushed myself to self-learn:  &lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Studied how the portal behaves behind the UI.
&lt;/li&gt;
&lt;li&gt;Explored the REST APIs that power MDM workflows.
&lt;/li&gt;
&lt;li&gt;Looked into open-source repositories on GitHub.
&lt;/li&gt;
&lt;li&gt;Broke down how &lt;strong&gt;Java&lt;/strong&gt;, &lt;strong&gt;JDKs&lt;/strong&gt;, and &lt;strong&gt;Maven&lt;/strong&gt; tie together in &lt;strong&gt;Carbon Kernel–based projects&lt;/strong&gt;.
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;At first, things like &lt;em&gt;API gateways&lt;/em&gt;, &lt;em&gt;publishing flows&lt;/em&gt;, and &lt;em&gt;claim-based authentication&lt;/em&gt; seemed abstract. But slowly, the architecture started making sense — I realized these weren’t just “APIs,” they were &lt;strong&gt;enterprise connectors between identity, security, and data&lt;/strong&gt;.  &lt;/p&gt;




&lt;h2&gt;
  
  
  🧩 Connecting the Dots: From Internship to My Own Projects
&lt;/h2&gt;

&lt;p&gt;While experimenting, I even evaluated &lt;strong&gt;Entgra UEM 6&lt;/strong&gt; (using my &lt;em&gt;Alpha Tech&lt;/em&gt; business email). That opened doors to &lt;strong&gt;WSO2 API publishing features&lt;/strong&gt;, which taught me that:  &lt;/p&gt;

&lt;p&gt;✅ APIs aren’t just direct DB calls — they’re published assets, controlled, secured, and monitored.&lt;br&gt;&lt;br&gt;
✅ A single published API serves all users/tenants, while tokens and claims decide whose data flows through.&lt;br&gt;&lt;br&gt;
✅ Enterprise systems solve the question:  &lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;“How do I ensure each user only sees their devices, even though everyone is calling the same endpoint?”&lt;/em&gt;  &lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ff8nylhcrw67g5lvqygng.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ff8nylhcrw67g5lvqygng.png" alt=" " width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  🧠 Applying It: Building My Own System
&lt;/h2&gt;

&lt;p&gt;This was a big shift. I wasn’t just thinking like an intern anymore — I was thinking like:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A &lt;strong&gt;developer&lt;/strong&gt; building scalable solutions.
&lt;/li&gt;
&lt;li&gt;A &lt;strong&gt;founder&lt;/strong&gt; shaping my own product direction.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;I applied these lessons in my own project — &lt;strong&gt;Alpha Connect Hub (under Alpha Tech)&lt;/strong&gt;:  &lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1r3u8tx03ik3sn3oc95w.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1r3u8tx03ik3sn3oc95w.png" alt=" " width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Built a &lt;strong&gt;Node.js backend&lt;/strong&gt; for device management.
&lt;/li&gt;
&lt;li&gt;Used &lt;strong&gt;WSO2 API publishing&lt;/strong&gt; to expose those APIs securely.
&lt;/li&gt;
&lt;li&gt;Integrated &lt;strong&gt;OAuth2 / JWT-based access tokens&lt;/strong&gt; to ensure each request is linked to a unique user identity.
&lt;/li&gt;
&lt;li&gt;Experimented with building a &lt;strong&gt;Java backend&lt;/strong&gt; to simulate MDM/EMM workflows on a &lt;strong&gt;Carbon Kernel stack&lt;/strong&gt;.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Far1ww8wk411vr99ogeyl.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Far1ww8wk411vr99ogeyl.png" alt=" " width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  ⚙️ Lessons From the Struggle
&lt;/h2&gt;

&lt;p&gt;This journey wasn’t smooth:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Running large Carbon Kernel projects on macOS was painful.
&lt;/li&gt;
&lt;li&gt;Debugging JDK versions, Maven builds, and UEM server issues tested my patience.
&lt;/li&gt;
&lt;li&gt;Figuring out why &lt;code&gt;GET /devices&lt;/code&gt; worked only via the API Gateway (and not as a direct DB call) forced me to learn about &lt;strong&gt;invoker endpoints&lt;/strong&gt;, &lt;strong&gt;token claims&lt;/strong&gt;, and &lt;strong&gt;mediation policies&lt;/strong&gt;.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;I learned that &lt;strong&gt;one API is published for everyone&lt;/strong&gt;, but the &lt;strong&gt;token’s claims (like user_id)&lt;/strong&gt; make it unique per user.  &lt;/p&gt;

&lt;p&gt;Every error — from a &lt;em&gt;401 auth failure&lt;/em&gt; to a &lt;em&gt;class-not-found exception&lt;/em&gt; — taught me something new.  &lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Through this struggle, I learned the real difference between project-level coding vs. enterprise-level development:&lt;/strong&gt;  &lt;/p&gt;

&lt;p&gt;&lt;em&gt;Projects require coding skill.&lt;/em&gt;&lt;br&gt;&lt;br&gt;
&lt;em&gt;Enterprise systems require architecture, patience, and persistence.&lt;/em&gt;  &lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  🌐 What’s Next
&lt;/h2&gt;

&lt;p&gt;I’m now preparing to set up a &lt;strong&gt;Linux server environment&lt;/strong&gt;, since Carbon Kernel–based systems run more stably there compared to macOS.  &lt;/p&gt;

&lt;p&gt;&lt;strong&gt;My roadmap is clear:&lt;/strong&gt;  &lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Build enterprise-ready backend systems.
&lt;/li&gt;
&lt;li&gt;Combine MDM, EMM, and API publishing into scalable, secure products.
&lt;/li&gt;
&lt;li&gt;Use this foundation to grow &lt;strong&gt;Alpha Tech&lt;/strong&gt; into a company that builds &lt;strong&gt;solutions&lt;/strong&gt;, not just apps.
&lt;/li&gt;
&lt;/ol&gt;




&lt;h2&gt;
  
  
  💡 Final Reflection
&lt;/h2&gt;

&lt;p&gt;Looking back, this wasn’t just an internship. It was the spark that helped me:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Transition from &lt;strong&gt;learning projects → building products&lt;/strong&gt;.
&lt;/li&gt;
&lt;li&gt;Move from &lt;strong&gt;coding → thinking enterprise&lt;/strong&gt;.
&lt;/li&gt;
&lt;li&gt;See technology not just as tools, but as part of a &lt;strong&gt;bigger ecosystem&lt;/strong&gt; of identity, security, and scale.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;My journey into enterprise development has only just begun. 🚀&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>internship</category>
      <category>mdm</category>
      <category>mercurialminds</category>
      <category>emm</category>
    </item>
  </channel>
</rss>
