Engineering notes
Things we’ve learned the hard way.
Short write-ups from real work: what broke, the code or command that fixed it, and the rule we follow now. Client names and identifying details are left out.
- MobileThe error message was on screen. The keyboard was on top of it.An automated UI test found the wrong-password message and passed, over and over. On a real phone, nobody could see it.
- MobileA 30-minute timer that stopped running when the phone went to sleepWe patched the symptom twice before replacing the thing that was actually wrong. Here's how that happened, and the fix.
- MobileWhere a session token should live on iOSUserDefaults is convenient, and it's a plain property list. Tokens belong in the Keychain, with an accessibility class chosen on purpose.
- WebWebhooks arrive twice. Build for it.Payment and messaging providers retry on timeouts, so the same event can show up more than once. Handling it takes one table and one transaction.
- WebThe page was slow because it asked three questions one at a timeServer-rendered pages often wait on independent requests in sequence. Tracing makes it obvious; the fix is usually a few lines.
- SecurityWhat we look at first when we unpack a mobile buildBefore any dynamic testing, the shipped binary tells you a lot. These are the first commands we run and what they tend to turn up.
- SecurityYour front-end bundle is public. Check what's in it.Secrets leak into JavaScript bundles through one misnamed environment variable or one wrong import. Checking takes a single command.
- DatabaseN+1 queries: the ORM wrote them, not youA list page that runs one query per row looks fine in development and falls over in production. Here's how to spot it from the database side.
Recognize one of these?
If your app or site has a problem that sounds familiar, tell us about it. A few paragraphs is enough to start.