Pieter Germishuys
banner
pgermishuys.bsky.social
Pieter Germishuys
@pgermishuys.bsky.social
"Is someone actually building anything, can someone please build something?" architure 2021
Reposted by Pieter Germishuys
The `FakeTimeProvider` in #dotnet is excellent for testing time-based scenarios. You can advance time in increments, like a true Time Lord, to test tricky timing behaviors.

Get it in the "Microsoft.Extensions.TimeProvider.Testing” NuGet package.
September 29, 2025 at 7:13 PM
Are the LLM based platforms for building products and services the "nocode" of the future?
We've been here before or is this different?
September 30, 2025 at 7:00 AM
Reposted by Pieter Germishuys
Livestream coming up! 📺

Token Management: Applying the Duende Backend for Frontend (BFF) Security Framework

🗓️ June 4, 2025
⏱️ 10 EST / 16:00 CEST / 14:00 UTC
🗣️ Speaker: Erwin van der Valk

Register here: duende.link/wj42025 #dotnet #security #bff
Token Management
We help companies using .NET to build identity and access control solutions for modern applications.
duende.link
May 19, 2025 at 11:02 AM
Reposted by Pieter Germishuys
We prepped for this yesterday, and it's shaping up to be a focused, hands-on experience. Spots will be limited to 7 participants per facilitator to ensure everyone can get deeply involved.

Hope to see you at DDD Europe in just over two weeks! More info:
2025.dddeurope.com/program/inte...
DDD Europe 2025 - Program
Henning Schwentner, Kenny Baas-Schwegler, Krisztina Hirth and Maxime Sanglan-Charlier
2025.dddeurope.com
May 20, 2025 at 6:51 AM
Reposted by Pieter Germishuys
Absolutely honored to have been on the Dotnet Rocks show with @richcampbell.bsky.social and @carlfranklin.bsky.social to talk about the BFF security pattern.

Check it out at: www.dotnetrocks.com/details/1950
bsky.app
May 15, 2025 at 7:15 AM
Reposted by Pieter Germishuys
Neat. Ubuntu is going to use sudo-rs starting in 25.10. trifectatech.org/blog/memory-...
Memory-safe sudo to become the default in Ubuntu - Trifecta Tech Foundation
trifectatech.org
May 7, 2025 at 1:53 AM
Reposted by Pieter Germishuys
ATT Internet peeps - can we all someone request an A.M.A. from someone/some-people at GitHub who are making the calls on it's direction.

We (the internet) have SO.MANY.QUESTIONS and you're all freaking/pissing us off.

Some on BSKY please make this happen.

Love: The Internet.

(retweet, etc)
April 29, 2025 at 2:00 AM
Reposted by Pieter Germishuys
Secure machine-to-machine communication?

In this video, Roland walks you through the #oauth2 Client Credentials flow. It's relatively straightforward, and a great way to get introduced to OAuth.

📺 youtu.be/_ncPlNlcavo

#oauth2 #identityserver #accesstoken #dotnet #security
April 24, 2025 at 12:59 PM
We are releasing our largest model yet. AGI in a couple of months.

Actually, hold on.. we don't really know if we should be giving our largest model a name, let alone whether calling it model 'x' is meaningful.

*one month later*

Our largest model now has a name and we'll be releasing it soon
April 6, 2025 at 4:45 PM
Been using AI to build a real-estate listing website. I asked it to provide a publicly accessible link to it so I can share.

Let me know what you think. 127.0.0.1.

Next, i'll be asking it to store the listing's as I complained that every time I restart the webserver, my listings disappear.
April 5, 2025 at 11:23 AM
Reposted by Pieter Germishuys
A common attack web devs need to guard against is Cross-Site Request Forgery (CSRF).

🦸‍♀️ Anti-Forgery tokens to the rescue!

Let's see how they work in more detail 👇
duende.link/wk7e6sg #dotnet #aspnetcore
March 25, 2025 at 1:32 PM
Apparently middleware is dangerous.... in Nextjs.
nextjs.org/blog/cve-202...
news.ycombinator.com/item?id=4344...

Me: AI Fix CVE-2025-29927
AI: *Rewrites entire app*
CVE-2025-29927
Next.js version 15.2.3 has been released to address a security vulnerability CVE-2025-29927.
nextjs.org
March 26, 2025 at 4:43 PM
The Vibing of the coding just ended.
"as if millions of voices suddenly cried out in terror and were suddenly silenced"
March 22, 2025 at 12:44 PM
New achievement unlocked: Mob Vibe Coding.
March 21, 2025 at 2:09 PM
"Vibe coding is coding where you fully trust AI and don't even read the code and just follow the vibes."
March 14, 2025 at 7:35 AM
Reposted by Pieter Germishuys
Today, I'm doing back-to-back talks at NDC Security 2025. In this second talk, I'm discussing how a previous talk at NDC resulted in me joining as a co-author of the OAuth spec for browser-based apps. Grab the slides here: https://buff.ly/4fMgG8Z #appsec #infosec
Breaking and securing OAuth 2.0 in frontends
Discover the underestimated threat of Cross-Site Scripting (XSS) in OAuth 2.0 Single Page Applications. Learn about hacks on frontend OAuth clients and explore solutions like the Backend-for-Frontend…
buff.ly
January 23, 2025 at 9:21 AM
Generative AI Blockchain, what else did I miss from the last 4 years.
January 11, 2025 at 8:42 AM
Life is short, remember that, it really provides some perspective.
January 11, 2025 at 8:41 AM
Happy new year!!!
January 1, 2025 at 8:34 PM
Merry belated Christmas y'all. Hope you spent the time with family and loved ones.
December 26, 2024 at 10:12 AM