Blog
Short, practical articles about what I learned on my own projects. With anonymised, real code excerpts.
Bot protection for a contact form without a captcha
Five invisible layers that stop most unwanted messages, while a real visitor has to do nothing at all.
A Laravel gotcha: the throttle counter is shared
throttle:5,1 and throttle:120,1 use the same counter per IP. That is how my analytics beacon used up the form's allowance.
A strict CSP in Laravel, with Vite
How I allow my own inline scripts with a one-time identifier, and block everything else.
Uploading large files in Laravel without breaking
How I solved uploading large videos so that one interrupted request does not take the whole upload with it.
How not to send the wrong email to the wrong person
Sending is the easy part of email campaigns. These are the safeguards I built into my own system.
Updating a mobile app without waiting for the app stores
How small fixes reach phones without interrupting a check-in.
When is it safe to retry a call?
A simple rule that stops someone from being admitted twice: only retry calls that are safe to repeat.
Sending webhooks with retries, without sending twice
Retries with growing delays and a locked check, so the same callback does not go out twice.
Rewriting a legacy system while it runs
How I replace an old system while users keep working: identical behaviour, a list of differences, audit logging.
Analytics that does not bloat the database
Daily summaries, re-runnable calculation and deleting only after the rollup: how history survives.