Did very little changes to tsconfig during past 6 months adoption
My day-to-day process - get the new package unless it some antd6, echart or some rendering engine or geo spatial lib, clean up with Claude, strict and unify type system and align it with my vite, tsconfig, oxlint tastes. The result - no need to follow libs bloat and supply chain attack issues. Easy to read, easy to fix.
the original sin of internet - it’s not secure, and for many it’s not the bug it’s a feature to make money or gain power. all nested layers to cover up previous fails. example - nonce, state, encryption bumps in oidc/oauth2.1
Mixed fealings cause the full context should include plans on both Authorization and Authentication flows at least withing Cloudflare ecosystem. No github examples
Anyway good start in the right direction from Cloudflare, yet still long way to go especially compare to the full Ory's offering its built on. Ory's Kratos handles identity, login, registration, recovery, MFA... https://github.com/ory
IMHO full scope should include plans on user store, SAML, multi-tenant org model. Good example - Zitadel https://github.com/zitadel has managed UI for orgs multitenancy, OIDC/PKCE supports, etc you can even partial glue RBAC to it
Siding "MCP is dead, Skills forever" what bother me about all of them is planning to plug MCPs and rotate keys ... this start hitting the fan very soon
Having recently gone through this exercise with our IAM vendor to secure our MCP service, OAuth DCR scares me in that context. With redirect flows, which are usually what you're using when you're plugging your MCP into an agent, the spec says nothing about how to secure that. I really don't want to allow just anybody to register a client with an arbitrary callback. That's opening us up to phishing. Register your client with a malicious callback url and then trick users into clicking a link that initiates that flow. Our legitimate idp will authenticate them and then send then hand their access tokens off to an attacker.
The spec handwaves around this talking about initial access tokens which a client would obtain first in order to register but the details are sparse and probably unworkable when we're talking about every end user being a client.
Ideally i would be able to specify an allowlist of redirect patterns so i could limit it to say, chatgpt or whatever else. But that would be a non-standard behavior so my IAM vendor isn't in a hurry to do it.
My expectations to dear fellow humans - more sophisticated personal insults (ex. give me your cute comments), a freudian slips, hidden messages and motives, first viewer experience with the next cool toy from the hype train, sharing all kind of insecurities, heavy f.. word if very dramatic first person experience happened, border line exposure to the insider info, sharing something your corporate HR gestapo wont appreciate but might help another guy on the line, "i knew the guy who actually did it" stories, motivational statement toward my non-native english, etc
real learning- copy paste the content and ask for “critical and constructive feedback and potential false narratives from industry professionals” to get 10x from it
From the first sentences, it looks like a 0.1x value. Discrediting the expanded hacker concept just because, criticizing its non-pc language, shaming on the small imoralities (in an industry full of life ruining unethical practices). The list goes on, and I didn't read everything!
In practice, that prompt gets chatgpt role-playing as industry professionals: who knows if it's near or far from the real deal.
Also, reading long texts is good for comprehension. You don't learn with reading summaries, you learn with repetition and even further if write your own summaries.
Real tip - find someone who loves outbound, can create a funnel outside of Linkedin or convert traffic from Linkedin to something more reliable and can talk about numbers non-stop for hours.
Ex. I never did more than 1k whatsapp messages with 20% open rate in a month ...
Know a friend who is doing 190k MRR with 12k whatsapp messages open rate 40%-60% (no AI SDRs!, fake avatars, etc) and what to double it next year. All he wants to talk is outbound ... and how it will make rich and how it should cost no more than 20% revenue.
99,999% hates outbound with passion, want to dump on someone else, can't retain SDRs for more than 6 months, etc
the pain point presented correctly especially comparison … but what about remedy?
https://github.com/cloud-in-a-bottle/cloud-in-a-bottle/
reply