Category
Kept out of source code entirely, injected at runtime, scoped narrowly, and rotatable without a deployment — and the reason this matters is that a secret committed to a repository is permanently
Delegated authorisation — letting an application act on a user's behalf against another service, without the user handing over their password. It is frequently described as a login mechanism, which
A JSON Web Token is a signed, self-contained token carrying claims — typically who the user is and when the token expires — which a server can verify without a database lookup. That property is its
Cross-site request forgery makes a user's browser send a request they did not intend, to a site where they are already authenticated — exploiting the fact that browsers attach cookies automatically
An attack where attacker-controlled content is executed as JavaScript in another user's browser, in the context of your site — which means it runs with that user's session, cookies and permissions.
An attack where user input is interpreted as SQL code rather than as data — and it happens for one reason: the query was built by concatenating strings, so the database cannot tell your instructions
A property of a language or system guaranteeing that a program cannot access memory it should not — no reading past the end of a buffer, no using freed memory, no dereferencing invalid pointers. Its
Managing change in an interface other people depend on — where the governing constraint is that once an API is published, you no longer control when consumers update, and in many cases they never
A good name states what the thing is, in the language of the problem, so a reader does not have to reconstruct it from the code. Naming matters because code is read far more often than it is written,
Because estimating software means estimating work that has never been done before — if it had, you would copy it — and human judgement about novel work is systematically biased in a direction that is
A genuine design disagreement rather than a settled question — and the honest answer is that the two approaches differ in what they make visible in the type system and what they make easy to ignore.
Log what you would need to diagnose a problem you cannot reproduce — and never log anything that turns your log store into a liability. Most logging is written for the moment it is added rather than
Three mechanisms for coordinating concurrent access to shared state, at different levels of abstraction — and choosing the wrong one is how concurrency bugs are introduced. Atomic operations. A
Which lines were executed while the tests ran — and nothing at all about whether those lines were checked, or whether the behaviour is correct. It is a measure of what was not tested, which is
Replacing a real dependency with a controlled stand-in, so a test can run fast, deterministically, and without touching a network, database or clock. It is essential and it is the most commonly
A practice of writing a failing test before the code that satisfies it, in a short cycle — red, green, refactor. The evidence for its claimed benefits is mixed and weaker than advocates suggest,
Reverting to the previous version versus fixing forward with a new release — and which is appropriate depends on factors that are worth deciding before an incident rather than during one. Rollback.
An artifact is the packaged output of a build — a compiled binary, a container image, a library archive — and reproducibility means that building the same source produces an identical artifact, every
Deliberately injecting failure into a system to discover how it behaves — on the reasoning that failures will occur anyway, and it is better to discover the consequences during working hours than at
Being responsible for responding to production incidents outside working hours — and it is one of the more consequential aspects of software work for people's lives, and one of the least well
Three related things at different levels: an indicator is what you measure, an objective is the target you set internally, and an agreement is the contractual promise with consequences. Service Level
A review after an incident that focuses on understanding what made the failure possible rather than on identifying who caused it — and the reason it works is practical rather than cultural
How new code is exposed to users — blue-green switches everyone at once between two complete environments; canary exposes a small proportion first and increases gradually. Blue-green deployment. Two
Defining servers, networks, databases and everything else supporting an application in files that are version-controlled and executed, rather than configuring them by hand through a console or by