18 Aug 2026 4 min read software-engineering The Schema Blind Spot: Deconstructing XSS via Object Injection in Form Parsers A teardown of how permissive TypeScript form libraries can inadvertently facilitate XSS by validating types but ignoring payload structure. WBSS Learning This post is for subscribers only Subscribe now Already have an account? Sign in
16 Aug The Hidden Bridge: How Zod Validates UI Events in Large-Scale Next.js Applications A form submission loses its type guarantee mid-flight, and Zod recovers the broken state. 16 Aug 2026 2 min read
15 Aug The Ghost Schema That Slips Past Your Type Guard A missing optional field in a Zod schema allowed a production crash despite passing static type checks. 15 Aug 2026 2 min read
13 Aug Zero‑Allocation Deserialization with Zod Proxies: A High‑Throughput Technique A pragmatic approach to deserializing JSON streams in TypeScript using Zod and Proxies, reducing GC pressure while keeping full type safety. 13 Aug 2026 4 min read
13 Aug Ensuring Consistency: A Helm + Zod Checklist for Type‑Safe Kubernetes Deployments A step‑by‑step checklist that shows how Zod‑validated Helm values guarantee Gonggong releases match expected service configs. 13 Aug 2026 4 min read
13 Jul Type‑Safe Code Generation with Custom TypeScript AST Transformers: A Practical Toolkit for Next.js and Node.js Boilerplate 13 Jul 2026 7 min read