Latest posts
Fresh from the blog
Learn Angular Prerendering Without SSR Using outputMode Static
This article demonstrates how to prerender every route of an Angular app at build time with no SSR server — including dynamic blog routes — and which routes must stay client-side.
Oct 9, 2026
Learn How to Add a Timeout to Every Server-Side HTTP Call in Node.js
This article demonstrates how one hung connection killed an entire Angular prerender build, and the two small changes that fixed it — AbortSignal.timeout and an SSR-only HTTP interceptor.
Oct 8, 2026
Learn Angular DomSanitizer and bypassSecurityTrustHtml Safely
This article demonstrates when it is acceptable to call bypassSecurityTrustHtml in Angular, using a Markdown blog renderer — and what changed the day an editor started writing that field.
Oct 6, 2026
Learn Spam Protection Using Honeypot, Rate Limit and CAPTCHA
This article demonstrates four layers of spam protection on a public comment form — a honeypot, a rate limit, a CAPTCHA and a moderation queue — and why each one fails differently.
Oct 5, 2026
Learn Security Headers and CSP Using Azure Static Web Apps
This article demonstrates how to set security headers and a Content Security Policy in staticwebapp.config.json — and how to widen the policy for every third-party script you add, without opening it fully.
Oct 2, 2026
Learn Which Settings Must Differ Between Local Development and Production
This article demonstrates the settings that cannot be the same on your machine and in Azure — the Secure cookie flag, captcha test keys, the storage emulator — and how to switch them without an isLocal flag.
Oct 1, 2026