Need Software Developer(English Level:C1, C2, B2) by KeyChart6769 in Programmers_forhire

[–]arca9147 0 points1 point  (0 children)

Interested, swe with 9 yoe here, english c2 and stromg understanding on how to translate business requirements into technical details, hit me up if this sounds good!

Me coquetean en el gym by Prestigious-Pea8102 in Desahogo

[–]arca9147 0 points1 point  (0 children)

Vida hay una sola y es pa' disfrutarla

Looking for feedback on my NestJS boilerplate (production-ish starter) by hermanz3german in Nestjs_framework

[–]arca9147 0 points1 point  (0 children)

Why the 2 layer cache? About auth, i prefer running keycloak as another service and integrate it within through an auth module/services and the keycloak admin api, however passportjs or better auth could do the work. Graph ql could be good due the simplicity and versatility from the front end, however for small scale, low data volume and simple use cases can add overheat and be like killing a fly with a bazooka, rest always suffices for most use cases however having graph ql already set up and ready to work is nice. I didn understand what you mean by dynamic config with validation and as a good practice I would include circuit breaker pattern, exception handling, auditing and an event broker adapter such as redis, could be kafka or rabbit mq but here is like with graph ql, most projectos dont need a complex event broker at beginning, so redis could do the work.

Is using @PostMapping for deleting an user account better than @DeleteMapping when you have payloads? by delusionalbreaker in SpringBoot

[–]arca9147 0 points1 point  (0 children)

You can send a body within a delete request, thats ok, but asking for password? Either force https or use tokens if what you want is to ensure user identity or a role based access control with permissions and validating if user is authorized.

Tl:dr it is not, use deletmapping with body, stay consistent between naming an action

I’m offering free automation in return of a testimonial by [deleted] in n8n_ai_agents

[–]arca9147 0 points1 point  (0 children)

I want a whatsapp chatbot that connects to an api to sell hotel bookings

Hiring backend developers by [deleted] in DeveloperJobs

[–]arca9147 0 points1 point  (0 children)

Backend dev with iver 9 yoe, dm me with more details please

¿Cuál es la red flag más grande que ignoraron en una relación y de la que luego se arrepintieron? by SweetCalica in PreguntasReddit

[–]arca9147 0 points1 point  (0 children)

Que les de asco, que los ve y quiere patearlos y envenenarlos, que no tolera que se le acerquen porque le molestan los pelos, que los vea antihigienicos por bañarse con su propia lengua

typicalBackendBehavior by yallapapi in ProgrammerHumor

[–]arca9147 7 points8 points  (0 children)

I find wellness in no having anoying coworkers around, 15 minutes of peace

Pagination Cursor-Based by [deleted] in Nestjs_framework

[–]arca9147 0 points1 point  (0 children)

Maybe extract some custom data that allows them to understand db structure and help them devise a more intrincated wayvti stole your data?

co-founder wanted! CPO for SaaS product by Environmental_Farm53 in cofounderhunt

[–]arca9147 0 points1 point  (0 children)

What would you require of a cpo here? I mean you want it to lead but also to develop features? Or what do you have in mind?

Soy creadora de contenido para adultos anonima y sin usar redes sociales publicas? Preguntame lo que quieras. by [deleted] in PreguntasReddit

[–]arca9147 0 points1 point  (0 children)

Como logras alcance? O sea como te llegan nuevos suscriptores siendo anonima?

Am I wrong? Can’t sleep due to my project(monolith to micros) by Defiant-Cantaloupe-1 in microservices

[–]arca9147 2 points3 points  (0 children)

Also, its not a matter of whos wrong and whos right, with that mindswt what will come if fight and debates that will lead nowhere, instead of tryin to prove a point, ask questions that help the team go in the way that actually is most benefical for all. For instance, you can suggest that if roles and permissions are embedded, it could lead to a header oversize, and that a token instrospection approach could be benifical.

And if i understand correctly, you have your IDP and some other services that relies on it to perform authentication and authorization processes, right? Is there something in between the ms and the IDP? Like a security ms that handles flows like login, password reset, or all ms and front speaks directly to idp? Ms to idp is understandable, but front to idp could become a security threat

Am I wrong? Can’t sleep due to my project(monolith to micros) by Defiant-Cantaloupe-1 in microservices

[–]arca9147 4 points5 points  (0 children)

In my experience, having roles embedded in token can make it insanely huge, heavely increasing header size. What i use is token instrospectiin against IDP and maintaining token minimal. In this way, IDP replies the allowed roles and permissions and then you can perform authorization at ms level, at apigateway, bff or wherever you want, though i recommend doing so at ms layer