Skip to content
yceffort
PostsSeriesTagsAbout🧪 Research
KO

Tweaks

theme
accent palette
film grain
minimal mode
14 POSTS

Backend 1

  • â—† OG Scraping Server Design Notes · Part 2
    #security#nodejs#backend

    Building an OG Scraping Server in Node.js (2): How SSRF Gets Through

    A feature where the server opens a URL the user handed it has the textbook conditions for SSRF written into its spec. Six ways a whitelist gets bypassed first, then five defensive principles that block them, all actually run on Node. Strip IPv4-mapped by hand and it gets through in hex notation, undici lookup hook is never called when the host is an IP literal, and URL.hostname keeps the brackets on an IPv6 literal. The final post of a two-part design note on OG scraping servers.

    2026-08-22·25 min read
  • â—† OG Scraping Server Design Notes · Part 1
    #web-scraping#backend#nodejs

    Building an OG Scraping Server in Node.js (1): From Runtime Choice to Error Rate and Latency

    The "10% error rate" of a link preview server is a single number that five different kinds of failure got mashed into. This post works out why this workload is I/O bound at that TPS, where runtime choice actually diverges across four points, and then moves on to lowering the error rate with User-Agent and encoding. Node built-in TextDecoder turns CP949 extension characters into different characters without raising an error, and a scraped og:title is not an API response but user input. It also covers cache stampedes, negative caching, and a two-million-run simulation that verifies "P95 under one second" by working backwards from the cache hit rate. The first post of a two-part design note on OG scraping servers.

    2026-08-22·33 min read
  • â—† Kubernetes for Frontend Developers · Part 5
    #kubernetes#devops#web-performance

    Autoscaling Is Automatic but Not Instant: HPA's Timeline, Measured Segment by Segment

    Raise traffic 12x and it takes 31.5 seconds for a new pod to receive its first request. I pulled an itemized bill for those 31.5 seconds with a stopwatch: the structure dominated by the detection window, the conditions under which the autoscaler goes blind in the five minutes right after a deploy, the scale-down staircase, why memory-based HPA misfires on Node, and KEDA's preemptive scaling. Part 5 of the Kubernetes for frontend developers series.

    2026-08-10·25 min read
  • â—† Directive Deep Dive · Part 3
    #react#nextjs#caching

    'use cache' Directive Deep Dive: To the End of Cache Boundaries

    Build-time transformations, cache key serialization, ResumeDataCache, cacheHandler, and Cache Components - everything created by a single 'use cache' line

    2026-05-01·Updated 2026-09-04·40 min read
  • â—† The State of Next.js · Part 4
    #nextjs#web-performance#react

    Is Next.js Fast Enough?

    The uncomfortable truth benchmarks reveal

    2026-03-21·23 min read
  • â—† The State of Next.js · Part 2
    #nextjs#serverless#oss

    Why Cloudflare Rebuilt Next.js

    What question does vinext really ask?

    2026-03-17·20 min read
  • â—† The State of Next.js · Part 1
    #nextjs#serverless#backend

    The Rise and Fall of Next.js Edge Runtime

    Hey Edge Middleware, how have you been?

    2026-03-16·13 min read
  • â—† Directive Deep Dive · Part 2
    #react#nextjs#networking

    React Server Functions Deep Dive: To the End of "use server"

    What happens behind a single line of "use server"?

    2026-03-09·26 min read
  • #nodejs#security#javascript

    The Pitfalls of Node.js vm Module: Why It's Not a Sandbox

    A preview of section 5.2 (Pitfalls of the vm Module) from the upcoming Node.js Deep Dive book.

    2026-02-27·14 min read
  • #nodejs#book#backend

    Seeking Beta Readers for Node.js Deep Dive (Working Title)

    Please show lots of interest and support!

    2026-02-19·3 min read
  • #web-performance#memory#async

    How to Efficiently Process Massive JSON Responses

    How to survive when JSON.parse() becomes overwhelming

    2026-01-11·18 min read
  • #security#nextjs#react

    It's a React vulnerability, so why do I have to upgrade Next.js?

    CVE-2025-55182, CVE-2025-55184, CVE-2025-55183, and the React hidden inside Next.js

    2025-12-12·19 min read
  • #memory#nodejs#v8

    A Guide to Node.js Memory Limits and Leak Tracking

    A look at V8's generational garbage collection, adjusting heap memory limits, and practical ways to diagnose memory leaks.

    2021-12-13·7 min read
  • #ci-cd#git#devops

    Why GitHub Actions Cron Jobs Run Late, and What to Use Instead

    Why GitHub Actions scheduled workflows get delayed by dozens of minutes: the structural causes, and free alternatives that actually run on time.

    2021-01-24·4 min read
mailMail icongithubtwitter
yceffort
•
© 2026
•
https://yceffort.kr