Home Projects Portfolio Dashboard Export PDF Log in

Languages

English
189

Latest Updates

Documenting code, one commit at a time.

JWT 7 posts
×

Securing Beauty-Appointment-System: Implementing JWT Authentication and Role-Based Access Control

Securing an application is often the most critical step in moving from a functional prototype to a production-ready service. In the SBSofiaBartoli/beauty-appointment-system, we reached a point where basic API access was no longer sufficient. We needed to ensure that users were who they claimed to be and that they only performed actions permitted by their specific roles.

The Security Gap

0 JWT

Improving Maintainability in the Beauty Appointment System

Documentation Matters

In our ongoing work on the beauty-appointment-system, we recently addressed a challenge that often plagues growing codebases: stale or incorrect documentation. While technical debt usually refers to messy code, 'documentation debt' can be equally damaging, leading to confusion during feature implementation and maintenance.

Our recent focus was cleaning up metadata and

Securing NestJS Endpoints: Implementing JWT Authentication

Securing API endpoints is the gatekeeper moment for any SaaS platform. In the crm-saas-backend project, we recently focused on shifting from open access to a robust, identity-aware architecture using NestJS and JWTs.

The Challenge

As we scale our CRM capabilities, protecting sensitive business logic within our controllers became a priority. We needed a way to ensure that only authenticated

Adopting Immutability: Why We Removed Our Update Endpoints

In our work on the SBSofiaBartoli/crm-saas-backend project, we recently reached a significant milestone in our data architecture. We decided to pivot away from traditional update-heavy CRUD operations, favoring an immutable approach to record management.

The Problem with Traditional Updates

In our initial implementation, we treated records as mutable entities. Any change meant performing an

Securing File Uploads: Implementing Mime-Type Validation in CRM SaaS

In our crm-saas-backend project, we recently hit a bottleneck regarding data ingestion. Our users need to bulk-import client lists, and the system needed a robust way to ensure that only expected file formats enter our processing pipeline. Allowing arbitrary files is like inviting a stranger into your home without checking their ID—you never know what kind of malicious payload might follow.

Streamlining Data Ingestion: Implementing Robust DTOs in NestJS

Managing file imports in a growing SaaS platform often leads to a common bottleneck: inconsistent data structures entering the system. In the crm-saas-backend project, we recently addressed the need for stricter validation when processing batch imports, moving away from loose object handling toward structured Data Transfer Objects (DTOs).

The Challenge of Unstructured Imports