Blog
Notes on data structures & algorithms, system design, and things I learn along the way.
Learning DSA? Follow the structured path — ordered articles from recursion to dynamic programming.→Light in fibre is fast, but not fast enough to cross the world many times per page load. How a content delivery network caches your files at edges near users, what it can and can't cache, and how to control it with headers and purges.
Three numbers that describe how a page feels to a real user: how fast the main content appears, how quickly it responds, and how much it jumps around. What each one measures, the thresholds that count as good, and the fixes that move them.
No comparison sort can beat O(n log n) — but if you never compare, the rule doesn't apply. How counting sort sorts small-range integers in O(n + k), why stability matters, and how radix sort extends the trick to large numbers digit by digit.
ACID promises a lot, but the I — isolation — comes in levels, and the default one still lets concurrent transactions overwrite each other. What dirty reads, non-repeatable reads, phantoms and lost updates are, and the fixes that actually work.
The meaning of a web request hasn't changed in decades — the way it travels has. How HTTP/2 fixed HTTP/1.1's one-request-at-a-time problem, why it hit a new wall in TCP, and how HTTP/3 over QUIC gets around it.
Find the contiguous slice of an array with the largest sum — in O(n) time and O(1) memory. Why a negative running sum should always be dropped, how to recover the slice itself, and how the same idea solves stock prices, circular arrays and products.
Import one function from a library and you might ship all of it. How bundlers use the static structure of ES modules to drop unused exports, the things that silently defeat it — CommonJS, side effects, barrel files — and how to check what you're actually shipping.
When one server can't keep up, you can buy a bigger one or add more. Why scaling up is the right first move, why it eventually stops working, and what scaling out really costs: stateless servers, load balancers, and shared state.
A webhook is an API calling you instead of you calling it. How to verify that a request really came from the provider, why you should acknowledge fast and process later, and how to handle the retries, duplicates and out-of-order events that always come.
Cross-site scripting gets your own site to run an attacker's JavaScript in your users' browsers. How it happens, why escaping output is the real fix, the places frameworks can't protect you, and how a Content Security Policy limits the damage when something slips through.
148 posts · page 3 of 15