Design trade-offs in separating authentication identity from business identity, their relationship to multitenancy, and continuity for existing integrations.
IAM 用户模型:登录用户与业务用户的拆分取舍
从认证主体与业务主体的职责出发,讨论为什么拆分登录用户与业务用户,以及这种拆分与多租户模型的关系和取舍。
Pulling Permissions Out of the Menu: Design Trade-offs in an Authorization Kernel
The design decisions behind extracting authorization out of the menu model and converging it into a standalone component, and why each alternative was rejected.
把权限从菜单里拆出来:授权内核的几个设计取舍
记录把授权部分从菜单模型中拆出来、收敛成独立组件的几个关键设计决策,以及当时为什么不选另一条路。
从 Figma 到编码 Agent:设计上下文的结构化、缓存与校验
从成本约束出发,讨论设计 API 接入、凭据池调度、本地上下文缓存与校验,以及编码 Agent 的职责和验收边界。
PostgreSQL Index Bloat: Why Small Tables Can Have Huge Indexes
A PostgreSQL index bloat remediation note: why tables with little data can still carry huge B-tree indexes, why ordinary VACUUM does not shrink them, and how to combine REINDEX, redundant-index cleanup, and write-model changes.
PostgreSQL 索引膨胀复盘:为什么表很小,索引却很大
一次 PostgreSQL 索引膨胀治理复盘:表数据很小但索引巨大,普通 VACUUM 无法缩小 B-tree 文件,最终需要从索引重建、冗余索引治理和写入模型改造三层处理。
Per-Client Authorization Isolation at the Gateway: One IAM Platform for Multiple Applications
A gateway-level Per-Client authorization isolation design for protecting multiple applications with one IAM platform, covering X-Expected-Client-Id, access levels, and entitlement policy boundaries.
网关层 Per-Client 鉴权隔离:一个 IAM 平台保护多个业务应用
在统一 IAM 平台保护多个业务应用的场景下,通过网关层 Per-Client 鉴权隔离防止跨应用 Token 滥用,覆盖 X-Expected-Client-Id 机制、访问级别与 entitlement 策略链的设计边界。
HMAC Cookie + Redis SID Dual-Layer Sessions: Browser Session Governance in an OAuth2/JWT System
Managing browser sessions in an OAuth2/JWT system with a dual-layer structure: HMAC-signed cookies plus Redis-backed SIDs, aligning browser login state, token lifecycle, and revocation signals under one governance model.