All posts.
Every EasySpawn article, newest first — deploying AI-built apps, Claude Code, databases, security, and the infrastructure underneath.
217 posts · page 3 of 9
Validating Input With Zod: One Schema for Forms, APIs, and Types
Every trust boundary — request bodies, query strings, webhooks, environment variables, AI output — needs runtime validation TypeScript can't provide. Using Zod schemas at each boundary, sharing them between client and server, stripping unknown keys, and useful errors.
How to Update Your App's Dependencies Safely
The packages your app is built on get security fixes and new versions constantly. Ignore them and you accumulate risk; update carelessly and the app breaks. What version numbers mean, a safe routine for updating, how to handle security warnings, and how to let an AI do the tedious part.
How to Undo Almost Anything in Git (Including an AI Agent's Mess)
An agent committed to the wrong branch, rewrote files you needed, or ran a reset it shouldn't have. Git can almost always get your work back. Which undo command fits which situation — restore, revert, reset, and the reflog that rescues 'deleted' commits — explained with the exact commands.
Why TypeScript Makes AI-Generated Code Safer
Types turn a whole class of AI mistakes — invented properties, wrong arguments, forgotten null checks — into errors caught before the code runs. How TypeScript acts as a feedback loop for agents, the settings that matter, and the escape hatches AI uses to switch it off.
The Transactional Outbox Pattern: Reliable Events Without Dual Writes
Writing to your database and publishing an event can't be made atomic, so one eventually happens without the other. How the transactional outbox fixes it: polling relays vs CDC, ordering, at-least-once delivery, idempotent consumers with an inbox, cleanup, and monitoring.
A tmux Cheat Sheet for Long-Running Sessions (and AI Agents)
tmux keeps terminal sessions running after you disconnect — which is exactly what you want for a build, a dev server, or an AI agent working on a remote machine. The twenty commands that cover almost everything, a small config that makes it pleasant, and the habits for running agents inside it.
How to Test Your App Before Launch (Without Writing Tests)
You don't need to be a programmer to find most bugs before your users do. A practical, one-afternoon testing plan for AI-built apps: the journeys to walk through, the 'try to break it' checks, the security tests, and how to keep track of what you find.
The Terminal for Complete Beginners: 15 Commands You'll Actually Use
The black window with blinking text isn't as scary as it looks. What the terminal is, why AI coding tools use it, and the fifteen commands that cover almost everything a beginner needs — plus the few that deserve respect.
Technical Debt in AI-Built Apps: What It Is and When to Pay It Down
AI tools let you build fast, and some of that speed is borrowed. What technical debt is, the specific kinds AI-generated code accumulates — duplication, dead code, inconsistent patterns, no tests — how to tell when it's hurting, and a practical way to pay it down without a rewrite.
Supabase vs Firebase: Which Backend for Your First App?
Lovable and Bolt lean on Supabase; many tutorials use Firebase. How the two backends compare — database model, auth, security rules, real-time, pricing shape, and lock-in — and which one fits the app you're building.
Supabase Row-Level Security Explained (for People Who Didn't Write the Policies)
If your app talks to Supabase from the browser, row-level security is the only thing standing between your users' data and anyone who opens the developer tools. What RLS is, how to read the policies your AI tool wrote, the four mistakes that leave data exposed, and how to test it yourself.
Stuck in an AI Fix Loop? How to Break Out
You ask the AI to fix a bug. It says it's fixed. It isn't. Three rounds later, two other things are broken too. Why AI tools get stuck in loops, how to recognise one early, and a step-by-step way out that works far better than asking again.
Structured Logging: Logs You Can Actually Search
console.log('user saved') is useless at 3am when you need every request user 4812 made in the last hour. How structured logs work, what fields to include, request IDs that tie a request together, log levels that mean something, what never to log, and how logs make AI agents better debuggers.
How to Stop Bots From Running Up Your AI App's Bill
If your app calls an AI model on a user's behalf, every request costs you money — and a bot, a scraper, or one determined user can make thousands of them overnight. Rate limits, usage caps, provider spending limits, and the architecture that keeps a surprise bill from happening.
How to Stop an AI Agent From Deleting Your Production Database
In July 2025 an AI coding agent deleted a company's production database during a code freeze. It wasn't a freak event — it was the predictable result of giving an agent production credentials. Six controls that make it structurally impossible, not just unlikely.
Static vs Dynamic Websites: What's the Difference?
A static site is the same files for everyone; a dynamic site builds pages per request. What each means, where single-page apps and server rendering fit, why it matters for hosting, speed, SEO, and cost — and how to tell which one your AI tool built.
SSH Keys Explained: Set Them Up Once, Properly
SSH keys are how you log into servers and push to GitHub without passwords. What the two halves of a key pair do, how to create a modern one, using ssh-agent and a config file so you stop retyping things, and the habits that matter: passphrases, one key per device, never sharing a private key.
SQL vs NoSQL: Which Database Should a Beginner Choose?
Postgres or MongoDB? Supabase or Firebase? The real difference between SQL and NoSQL databases, what 'relational' and 'document' mean, where each shines, the myths about scale and flexibility, and why most new apps should start with SQL.
SQL Injection Explained: The Classic Attack and the One-Line Fix
SQL injection lets an attacker rewrite your database queries by typing into a form. How it works with a simple example, what damage it can do, why parameterized queries and ORMs prevent it, the places AI-generated code still gets it wrong, and how to check your app.
SQL for Beginners: The Queries You Need to Understand Your App's Data
You don't need to become a database expert to read your own data. The handful of SQL queries — SELECT, WHERE, ORDER BY, COUNT, JOIN — that let you answer real questions about your app, plus the two commands to be very careful with.
Soft Deletes and Audit Logs: Keeping History Without Making a Mess
Deleting rows is irreversible; hiding them has costs too. When to use soft deletes, how to implement them without leaking 'deleted' data (partial indexes, unique constraints, views, RLS), the privacy tension with erasure requests, and how to build an audit log with triggers or application events.
Social Preview Images: Make Your Links Look Good When Shared
When someone shares your app's link on Slack, X, LinkedIn, or iMessage, the preview card comes from Open Graph tags. What they are, the exact tags to add, the right image size, how to generate images per page in Next.js, how to test, and why your preview isn't updating.
"Sign in with Google" Explained: OAuth for Beginners
Social login lets users skip creating a password. How 'Sign in with Google' (and GitHub, Apple, Microsoft) actually works, what OAuth and OpenID Connect are, what redirect URIs and client secrets are, and why it breaks when you move from localhost to your real domain.
Should You Still Learn to Code If AI Writes It?
AI can now build working apps from a description, so is learning to code still worth it? An honest answer: what AI has genuinely made unnecessary, the skills that matter more than ever, and a practical learning path for people who build with AI.