# user

Published articles for user.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Rate limits on GitLab.com are changing

DevFeed: [Rate limits on GitLab.com are changing](<https://devfeed.tech/articles/rate-limits-on-gitlab-com-are-changing-41278.md>)

Original publisher: [Read original article](<https://about.gitlab.com/blog/rate-limit-change-2026/>)

Author: Sam Wiskow

Published: 2026-09-17T00:00:00Z

Content type: release

Language: en

Sources: [GitLab](<https://devfeed.tech/sources/gitlab.md>)

Topics: [GitLab](<https://devfeed.tech/topics/gitlab.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Users](<https://devfeed.tech/topics/users.md>), [account](<https://devfeed.tech/topics/account.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [automation](<https://devfeed.tech/tags/automation.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [limits](<https://devfeed.tech/tags/limits.md>), [platform](<https://devfeed.tech/tags/platform.md>), [product](<https://devfeed.tech/tags/product.md>), [user](<https://devfeed.tech/tags/user.md>), [users](<https://devfeed.tech/tags/users.md>)

### AI overview

GitLab.com will align rate limits with subscription tiers beginning October 19, 2026. Free accounts and unauthenticated requests change first, while Premium and Ultimate limits change in January 2027. Unauthenticated requests are limited to 60 requests per hour per IP address, with preview windows scheduled for October 7 and 14.

### Source excerpt

GitLab.com hosts millions of projects for teams of every size that need a platform they can rely on. Demand is climbing quickly, and we expect platform load to grow several times over this year. Predictable limits are what keep GitLab.com fast for everyone on it, including the automation and agent workloads teams are building on the platform. To hold that as we scale, we're updating how rate limits work. Starting October 19, 2026, rate limits on GitLab.com will align with your subscription tier. Free accounts and unauthenticated requests happen first, on October 19. Premium and Ultimate move in January 2027. What is changing Limits align with your subscription. Free, Premium, and Ultimate subscription plans get their own limits, applied per user and per top-level group. Free takes effect October 19; Premium and Ultimate in January 2027. Signing in gets you the full limit. An authenticated request is governed by your subscription plan below. A request that arrives with no credentials gets 60 requests per hour per IP address. The per-plan limits are published in the rate limits documentation. What happens on October 19 There will be two preview windows for Free and unauthenticated traffic, on October 7 and October 14 from 15:00 to 19:00 UTC. Signed-in Premium and Ultimate requests are not affected, since those limits do not change until January. Unauthenticated requests are capped no matter where they come from, including automation running against a paid account without credentials. A preview window (engineers call these brownouts) is a short, planned window where we switch the new limits on and then switch them back off. Nothing else about the service changes while it runs. The point is to give you a real look at how your own workloads behave under the new limits, weeks before they apply for good. On October 19 the new limits take effect. We set these limits by looking at how GitLab.com is actually used. Almost all users are already inside the new limits and won't n

## Invite Systems are an Open Relay

DevFeed: [Invite Systems are an Open Relay](<https://devfeed.tech/articles/invite-systems-are-an-open-relay-32356.md>)

Original publisher: [Read original article](<https://joshtronic.com/2026/07/19/invite-systems-are-an-open-relay/>)

Author: Josh Sherman

Published: 2026-07-19T00:00:00Z

Content type: opinion

Language: en

Sources: [Josh Sherman](<https://devfeed.tech/sources/josh-sherman.md>)

Topics: [systems](<https://devfeed.tech/topics/systems.md>), [email](<https://devfeed.tech/topics/email.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>)

Tags: [email](<https://devfeed.tech/tags/email.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [server](<https://devfeed.tech/tags/server.md>), [service](<https://devfeed.tech/tags/service.md>), [user](<https://devfeed.tech/tags/user.md>)

### AI overview

The article explains how invite systems can be abused for spam when users control organization names and platforms fail to limit invitation volume. It recommends sensible invite caps and monitoring for users who reach them.

### Source excerpt

Every time I think I've seen it all from spammers, they do something that surprises me. The ingenuity of bad actors is an interesting thing. I always wonder what sort of world we'd live in if their efforts were focused on good. What sucks the most is when they abuse something that's intended to bring people together. Case in point, an invite system. It exists to allow somebody the chance to get the rest of their team using a product or service. Invites wouldn't work if they said "You've been invited to platform" with no additional context. Typically the email states the name of the organization you're being invited to. "You've been invited to your organization name here". Where does that organization name come from? The user of course! And what happens if the user has ill intentions? They set the organization name to something like "Text 1-800-555-1212 for a good time", or something even sketchier than that. Generally speaking, these emails come through transactionally and from a generic email on the platform. If your system doesn't meter the number of invites, you have yourself a certified spam cannon! May as well set up an SMTP server without authentication, better known as an open mail relay. There's a few ways you can approach limits. Have a cap on the total number of pending invites? The spammer may delete pending invites to keep moving. Daily limits on total invites sent? Maybe they'll be okay with stretching their campaign over days? Probably not, most spammers are in the business of going as hard and fast as possible before they get caught. Occasionally somebody will fly below the radar, but I think that's more of a bug than a feature. Sane limits as to not get in the way of legitimate users tends to get you pretty far. Monitoring if/when somebody hits the limits is good too. Spammers usually won't write in to let you know they hit some limit. I say usually because there are some special folks out there that will come knocking.

## 'guix substitute' and 'guix pull' Vulnerabilities

DevFeed: ['guix substitute' and 'guix pull' Vulnerabilities](<https://devfeed.tech/articles/guix-substitute-and-guix-pull-vulnerabilities-34148.md>)

Original publisher: [Read original article](<https://guix.gnu.org/blog/2026/guix-substitute-pull-vulnerabilities//>)

Author: Caleb Ristvedt

Published: 2026-07-02T17:00:00Z

Content type: release

Language: en

Sources: [GNU Guix -- Blog](<https://devfeed.tech/sources/gnu-guix-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [upgrade](<https://devfeed.tech/topics/upgrade.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [mitm](<https://devfeed.tech/tags/mitm.md>), [root](<https://devfeed.tech/tags/root.md>), [security](<https://devfeed.tech/tags/security.md>), [security-advisory](<https://devfeed.tech/tags/security-advisory.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [user](<https://devfeed.tech/tags/user.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article details several security vulnerabilities in Guix substitute and guix pull, including remote privilege escalation, remote store corruption, possible disclosure of sensitive files, and file overwrite issues. It advises users to upgrade the Guix daemon and describes a regression affecting some unprivileged users.

### Source excerpt

Several security issues (CVE IDs pending) have been identified in guix substitute , a helper utility invoked by guix-daemon , which enable a variety of harmful activities including remote privilege escalation to the build daemon user , remote store corruption , and potentially local disclosure of sensitive files accessible to the build daemon user. All systems are affected, whether or not guix-daemon is running with root privileges; the harm that can be done when guix-daemon runs without root privileges is more limited. You are strongly advised to upgrade your daemon now (see...

## From Intern Project to Production: How I Shipped the Draw Tool for Canva's Present Mode

DevFeed: [From Intern Project to Production: How I Shipped the Draw Tool for Canva's Present Mode](<https://devfeed.tech/articles/from-intern-project-to-production-how-i-shipped-the-draw-tool-for-canva-s-present-mode-37930.md>)

Original publisher: [Read original article](<https://www.canva.dev/blog/engineering/draw-in-present-mode/>)

Author: Edwina Adisusila

Published: 2025-08-06T00:00:01Z

Content type: article

Language: en

Sources: [Canva Engineering](<https://devfeed.tech/sources/canva-engineering.md>)

Topics: [Development](<https://devfeed.tech/topics/development.md>), [Front end](<https://devfeed.tech/topics/frontend.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>), [real-time](<https://devfeed.tech/topics/real-time.md>)

Tags: [code-reviews](<https://devfeed.tech/tags/code-reviews.md>), [draw-tool](<https://devfeed.tech/tags/draw-tool.md>), [feature](<https://devfeed.tech/tags/feature.md>), [frontend](<https://devfeed.tech/tags/frontend.md>), [i](<https://devfeed.tech/tags/i.md>), [intern](<https://devfeed.tech/tags/intern.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [new-feature](<https://devfeed.tech/tags/new-feature.md>), [overview](<https://devfeed.tech/tags/overview.md>), [production](<https://devfeed.tech/tags/production.md>), [quality](<https://devfeed.tech/tags/quality.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [technical](<https://devfeed.tech/tags/technical.md>), [tool](<https://devfeed.tech/tags/tool.md>), [user](<https://devfeed.tech/tags/user.md>), [users](<https://devfeed.tech/tags/users.md>)

### AI overview

A Canva engineer describes evolving an internship proof of concept into the Draw in Present Mode feature and shipping it to production. The article covers user demand, implementation and testing, code reviews, release planning, analytics monitoring, and the technical challenge of integrating drawing into Canva's separate editor and presenting code domains.

### Source excerpt

Overview of the technical hurdles I overcame to evolve my intern project into a new feature for users.

## Data-Driven Debugging for Engineers

DevFeed: [Data-Driven Debugging for Engineers](<https://devfeed.tech/articles/data-driven-debugging-for-engineers-38658.md>)

Original publisher: [Read original article](<https://krossovochkin.com/posts/2025_06_03_data_driven_debugging_for_engineers/>)

Published: 2025-06-03T00:00:00Z

Content type: tutorial

Language: en

Sources: [Vasya Drobushkov](<https://devfeed.tech/sources/vasya-drobushkov.md>)

Topics: [debugging](<https://devfeed.tech/topics/debugging.md>), [bug](<https://devfeed.tech/topics/bug.md>), [Development](<https://devfeed.tech/topics/development.md>), [unit tests](<https://devfeed.tech/topics/unit-tests.md>), [Code](<https://devfeed.tech/topics/code.md>), [Users](<https://devfeed.tech/topics/users.md>)

Tags: [bugs](<https://devfeed.tech/tags/bugs.md>), [debugging](<https://devfeed.tech/tags/debugging.md>), [root](<https://devfeed.tech/tags/root.md>), [test](<https://devfeed.tech/tags/test.md>), [unit-tests](<https://devfeed.tech/tags/unit-tests.md>), [user](<https://devfeed.tech/tags/user.md>)

### AI overview

This developer article explains how engineers debug bugs reported by developers, QA, and users. It compares the role of unit tests and end-to-end tests, then describes the greater difficulty of diagnosing vague user-reported symptoms.

### Source excerpt

As engineers, we deal with bugs every day. Finding the root cause and delivering the right fix is one of our most essential -- and satisfying -- skills. In this post, I want to walk through different types of issues we face and how we typically debug them. Most importantly, I'll share my favorite and most challenging method: data-driven debugging. Let's break it down by who reports the issue and how it's discovered.

## Understanding fault tolerance in distributed systems

DevFeed: [Understanding fault tolerance in distributed systems](<https://devfeed.tech/articles/understanding-fault-tolerance-in-distributed-systems-36102.md>)

Original publisher: [Read original article](<https://temporal.io/blog/what-is-fault-tolerance>)

Author: Lauren Bennett

Published: 2025-01-08T00:00:00Z

Content type: article

Language: en

Sources: [Temporal Blog](<https://devfeed.tech/sources/temporal-blog.md>)

Topics: [distributed-systems](<https://devfeed.tech/topics/distributed-systems.md>), [systems](<https://devfeed.tech/topics/systems.md>), [Availability](<https://devfeed.tech/topics/availability.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Replication](<https://devfeed.tech/topics/replication.md>), [backups](<https://devfeed.tech/topics/backups.md>)

Tags: [availability](<https://devfeed.tech/tags/availability.md>), [backups](<https://devfeed.tech/tags/backups.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [data](<https://devfeed.tech/tags/data.md>), [distributed](<https://devfeed.tech/tags/distributed.md>), [distributed-systems](<https://devfeed.tech/tags/distributed-systems.md>), [downtime](<https://devfeed.tech/tags/downtime.md>), [failover](<https://devfeed.tech/tags/failover.md>), [fault-tolerance](<https://devfeed.tech/tags/fault-tolerance.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [outage](<https://devfeed.tech/tags/outage.md>), [replication](<https://devfeed.tech/tags/replication.md>), [services](<https://devfeed.tech/tags/services.md>), [software](<https://devfeed.tech/tags/software.md>), [systems](<https://devfeed.tech/tags/systems.md>), [temporal-concepts](<https://devfeed.tech/tags/temporal-concepts.md>), [user](<https://devfeed.tech/tags/user.md>)

### AI overview

An explanation of fault tolerance in distributed systems, including how it keeps systems operating during failures and limits disruptions, downtime, and data loss. It describes redundancy, replication, failover mechanisms, graceful degradation, and the relationship between high availability and fault tolerance.

### Source excerpt

Discover what fault tolerance is and how it ensures reliable systems with key principles and examples in cloud environments.

## API flaws in McDelivery India enabled discounted orders, order hijacking, and access to user information

DevFeed: [API flaws in McDelivery India enabled discounted orders, order hijacking, and access to user information](<https://devfeed.tech/articles/i-m-lovin-it-exploiting-mcdonald-s-apis-to-hijack-deliveries-and-order-food-for-a-penny-32612.md>)

Original publisher: [Read original article](<https://eaton-works.com/2024/12/19/mcdelivery-india-hack/>)

Author: Eaton

Published: 2024-12-19T13:00:22Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [API](<https://devfeed.tech/topics/api.md>), [Security](<https://devfeed.tech/topics/security.md>), [Web app](<https://devfeed.tech/topics/webapp.md>), [Website](<https://devfeed.tech/topics/website.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [bug](<https://devfeed.tech/tags/bug.md>), [security](<https://devfeed.tech/tags/security.md>), [service](<https://devfeed.tech/tags/service.md>), [user](<https://devfeed.tech/tags/user.md>), [web-app](<https://devfeed.tech/tags/web-app.md>)

### AI overview

A security disclosure describes API flaws in McDelivery India that enabled orders for INR 1, hijacking or redirecting other customers' deliveries, access to order details and invoices, order tracking, and exposure of sensitive driver information.

### Source excerpt

A series of API flaws in McDelivery India made it possible to order food for a penny, hijack other people's delivery orders, view user information, and more.

## Accessibility Considerations with Stacked Cards Custom Layout

DevFeed: [Accessibility Considerations with Stacked Cards Custom Layout](<https://devfeed.tech/articles/accessibility-considerations-with-stacked-cards-custom-layout-38487.md>)

Original publisher: [Read original article](<https://eevis.codes/blog/2024-07-25/accessibility-considerations-with-stacked-cards-custom-layout/>)

Author: Eevis Panula

Published: 2024-07-25T03:26:13.958000Z

Content type: tutorial

Language: en

Sources: [Eevis Blog](<https://devfeed.tech/sources/eevis-blog.md>)

Topics: [Accessibility](<https://devfeed.tech/topics/accessibility.md>), [User interface design](<https://devfeed.tech/topics/ui-design.md>), [Compose](<https://devfeed.tech/topics/compose.md>), [Android](<https://devfeed.tech/topics/android.md>)

Tags: [accessibility](<https://devfeed.tech/tags/accessibility.md>), [assistive-technology](<https://devfeed.tech/tags/assistive-technology.md>), [component](<https://devfeed.tech/tags/component.md>), [compose](<https://devfeed.tech/tags/compose.md>), [semantics](<https://devfeed.tech/tags/semantics.md>), [user](<https://devfeed.tech/tags/user.md>)

### AI overview

This article examines accessibility issues in a stacked-cards custom layout built with Compose. It focuses on Switch Access, where deleting a card causes focus to disappear, and discusses moving the click action to the stack component as a partial fix. It also considers improving content labels for Voice Access and notes that the coverage is not exhaustive.

### Source excerpt

A couple of weeks ago, I published a blog post Stacked Cards Layout With Compose - And Cats. The layout has some accessibility issues, and I aim to fix some of them in this blog post. There are a couple of issues I'm not fixing here because of the scope of this blog post; instead, I'm discussing the problems they're causing and possible solutions. This time, I will also be pointing out some things that are good about the layout. I feel like I'm often just talking about problems and trying to find them, but this time, I'll share something that's working well, too. Before we dive into the different aspects I chose for this blog post, here is a fair warning: This list is not extensive and doesn't contain all possible accessibility problems that this kind of layout might have. I didn't test with every possible assistive technology or setting. My goal was progress over perfection, and I believe that the modifications I'll list are already significant improvements to the accessibility of this layout. Switch Access The first assistive technology I'm going to talk about and improve the app for is Switch Access. It's a service that lets the user navigate their phone with one or more switches. If you want to learn more, the Android Accessibility Checklist I've created has a section about Switch Access: Test with Switch Access. When testing with Switch Access, there was one problem I could find: When removing a card from the stack, the focus didn't go anywhere. It just disappeared. The reason for that is that the component on which the focus was had been deleted, and the accessibility service lost the focus. One way to fix this issue is by moving the click event to the stack-component instead of the card itself. We can do this by adding a semantics-modifier with an onClick-lambda to the CardStack's modifier-property. Let's also move the lastItem outside the CardStack so that we can use it in the function we add: // MainScreen.kt val lastItem = catIds.value.last() CardStack( Mo

## Designing Harmony into Dynamic Color

DevFeed: [Designing Harmony into Dynamic Color](<https://devfeed.tech/articles/designing-harmony-into-dynamic-color-29254.md>)

Original publisher: [Read original article](<https://material.io/blog/dynamic-color-harmony>)

Published: 2022-02-10T13:00:00Z

Content type: article

Language: en

Sources: [Material.io - Material Design](<https://devfeed.tech/sources/material-io-material-design.md>)

Topics: [color](<https://devfeed.tech/topics/color.md>)

Tags: [color](<https://devfeed.tech/tags/color.md>), [custom](<https://devfeed.tech/tags/custom.md>), [design](<https://devfeed.tech/tags/design.md>), [user](<https://devfeed.tech/tags/user.md>)

### AI overview

Material explains how makers can design with custom colors while respecting user choice in dynamic color systems.

### Source excerpt

How Material enables makers to design with custom colors while respecting user choice

## How to Reduce Layout Reflow When Using Web Fonts

DevFeed: [How to Reduce Layout Reflow When Using Web Fonts](<https://devfeed.tech/articles/how-to-reduce-layout-reflow-when-using-web-fonts-29311.md>)

Original publisher: [Read original article](<https://material.io/blog/reduce-reflow-with-web-fonts>)

Published: 2021-09-09T09:00:00Z

Content type: tutorial

Language: en

Sources: [Material.io - Material Design](<https://devfeed.tech/sources/material-io-material-design.md>)

Topics: [Font](<https://devfeed.tech/topics/font.md>), [User Experience](<https://devfeed.tech/topics/user-experience.md>), [Web](<https://devfeed.tech/topics/web.md>)

Tags: [applying](<https://devfeed.tech/tags/applying.md>), [best](<https://devfeed.tech/tags/best.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [experience](<https://devfeed.tech/tags/experience.md>), [fonts](<https://devfeed.tech/tags/fonts.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [layout](<https://devfeed.tech/tags/layout.md>), [loading](<https://devfeed.tech/tags/loading.md>), [practices](<https://devfeed.tech/tags/practices.md>), [reduce](<https://devfeed.tech/tags/reduce.md>), [user](<https://devfeed.tech/tags/user.md>), [user-experience](<https://devfeed.tech/tags/user-experience.md>), [using](<https://devfeed.tech/tags/using.md>), [web](<https://devfeed.tech/tags/web.md>), [web-fonts](<https://devfeed.tech/tags/web-fonts.md>)

### AI overview

This article explains how applying font-loading best practices can reduce layout reflow when using web fonts and improve the user experience.

### Source excerpt

Applying best practices for font loading can help improve the user experience

## What You Need to Know to Manage Users in Django Admin

DevFeed: [What You Need to Know to Manage Users in Django Admin](<https://devfeed.tech/articles/what-you-need-to-know-to-manage-users-in-django-admin-33945.md>)

Original publisher: [Read original article](<https://hakibenita.com/what-you-need-to-know-to-manage-users-in-django-admin>)

Author: Haki Benita

Published: 2019-08-04T21:00:00Z

Content type: tutorial

Language: en

Sources: [Haki Benita](<https://devfeed.tech/sources/haki-benita.md>)

Topics: [Django](<https://devfeed.tech/topics/django.md>), [Django Admin](<https://devfeed.tech/topics/django-admin.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Users](<https://devfeed.tech/topics/users.md>)

Tags: [articles](<https://devfeed.tech/tags/articles.md>), [data](<https://devfeed.tech/tags/data.md>), [django](<https://devfeed.tech/tags/django.md>), [django-admin](<https://devfeed.tech/tags/django-admin.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [user](<https://devfeed.tech/tags/user.md>), [users](<https://devfeed.tech/tags/users.md>)

### AI overview

This article discusses how staff users in Django Admin can misuse permissive or misconfigured permissions on the user model, including potentially making themselves superusers. It presents ways to protect Django Admin and reduce the risk of human errors and data leaks.

### Source excerpt

Have you ever stopped to think what staff user can do in your Django admin site? Did you know staff users with misconfigured permissions on the user model can make themselves superusers? Permissive permissions to staff users can cause disastrous human errors at best, and lead to major data leaks and at worst.

## A Multiplatform Case Study for an Inclusive Virtual Try-on Experience - Frances

DevFeed: [A Multiplatform Case Study for an Inclusive Virtual Try-on Experience - Frances](<https://devfeed.tech/articles/a-multiplatform-case-study-for-an-inclusive-virtual-try-on-experience-frances-38152.md>)

Original publisher: [Read original article](<https://touchlab.co/a-multi-platform-case-study-for-an-inclusive-virtual-try-on-experience>)

Published: 2019-05-28T19:42:39Z

Content type: article

Language: en

Sources: [Touchlab | Enterprise Mobile Innovation & Development](<https://devfeed.tech/sources/touchlab-enterprise-mobile-innovation-development.md>)

Topics: [multiplatform](<https://devfeed.tech/topics/multiplatform.md>), [client](<https://devfeed.tech/topics/client.md>)

Tags: [case-study](<https://devfeed.tech/tags/case-study.md>), [design](<https://devfeed.tech/tags/design.md>), [discovery](<https://devfeed.tech/tags/discovery.md>), [e-commerce](<https://devfeed.tech/tags/e-commerce.md>), [experience](<https://devfeed.tech/tags/experience.md>), [gender](<https://devfeed.tech/tags/gender.md>), [inclusive](<https://devfeed.tech/tags/inclusive.md>), [multiplatform](<https://devfeed.tech/tags/multiplatform.md>), [retail](<https://devfeed.tech/tags/retail.md>), [user](<https://devfeed.tech/tags/user.md>)

### AI overview

Touchlab describes a one-week, platform-agnostic design sprint to create a user-centric e-commerce virtual try-on experience for a makeup brand. The case study emphasizes inclusive research, contextual inquiry, and the varied personal meanings of makeup.

### Source excerpt

Multiplatform Case Study: Our goal? To design a user-centric, e-commerce experience for a single makeup brand in one week.

## 18. Правило "2x"

DevFeed: [18. Правило "2x"](<https://devfeed.tech/articles/18-2x-30287.md>)

Original publisher: [Read original article](<https://www.mdubakov.com/posts/2x-rule>)

Published: 2018-04-02T15:02:57Z

Content type: opinion

Language: ru

Sources: [Blog by Michael Dubakov](<https://devfeed.tech/sources/blog-by-michael-dubakov.md>)

Topics: [Agile](<https://devfeed.tech/topics/agile.md>)

Tags: [agile](<https://devfeed.tech/tags/agile.md>), [product-owner](<https://devfeed.tech/tags/product-owner.md>), [user](<https://devfeed.tech/tags/user.md>)

### AI overview

The author argues that software development estimates are routinely too optimistic, proposing an empirical "2x rule": experienced teams often take twice as long as initially expected, while inexperienced teams may take three times as long. The article attributes poor estimates to uncertainty and recommends using spikes to gain knowledge and improve estimates.

### Source excerpt

Поговорим о том, почему сроки в разработке ПО *всегда* проебываются.

## How Tag Managers Can Harm Website Performance and User Experience

DevFeed: [How Tag Managers Can Harm Website Performance and User Experience](<https://devfeed.tech/articles/tags-gone-wild-managing-tag-managers-31305.md>)

Original publisher: [Read original article](<https://nystudio107.com/blog/tags-gone-wild>)

Author: andrew@nystudio107.com (Andrew Welch)

Published: 2017-04-19T18:41:00Z

Content type: article

Language: en

Sources: [nystudio107 | Articles on modern web development.](<https://devfeed.tech/sources/nystudio107-articles-on-modern-web-development.md>)

Topics: [Website](<https://devfeed.tech/topics/website.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [User Experience](<https://devfeed.tech/topics/user-experience.md>), [Latency](<https://devfeed.tech/topics/latency.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [Web Development](<https://devfeed.tech/topics/web-development.md>), [browser](<https://devfeed.tech/topics/browser.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [adobe](<https://devfeed.tech/tags/adobe.md>), [browser](<https://devfeed.tech/tags/browser.md>), [caching](<https://devfeed.tech/tags/caching.md>), [capabilities](<https://devfeed.tech/tags/capabilities.md>), [detrimental](<https://devfeed.tech/tags/detrimental.md>), [experience](<https://devfeed.tech/tags/experience.md>), [google](<https://devfeed.tech/tags/google.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [latency](<https://devfeed.tech/tags/latency.md>), [like](<https://devfeed.tech/tags/like.md>), [manager](<https://devfeed.tech/tags/manager.md>), [offer](<https://devfeed.tech/tags/offer.md>), [performance](<https://devfeed.tech/tags/performance.md>), [tools](<https://devfeed.tech/tags/tools.md>), [user](<https://devfeed.tech/tags/user.md>), [user-experience](<https://devfeed.tech/tags/user-experience.md>), [web](<https://devfeed.tech/tags/web.md>), [website](<https://devfeed.tech/tags/website.md>), [wonderful](<https://devfeed.tech/tags/wonderful.md>)

### AI overview

The article explains that Google Tag Manager and Adobe Tag Manager let marketing and analytics professionals inject arbitrary JavaScript tags into webpages. It warns that tags can load additional tags, increasing browser requests, DNS lookups, and dependence on external servers, which can degrade website performance and user experience, especially on high-latency mobile connections.

### Source excerpt

Tools like Google Tag Manager and Adobe Tag Manager offer wonderful capabilities, but they can be detrimental to user experience

## Using search to guess job categories in FINN småjobber

DevFeed: [Using search to guess job categories in FINN småjobber](<https://devfeed.tech/articles/category-guessing-32012.md>)

Original publisher: [Read original article](<https://tech.finn.no2017/02/02/category-guessing/>)

Author: Tor Arne Kvaløy

Published: 2017-02-02T14:14:30Z

Content type: tutorial

Language: en

Sources: [Finn.no](<https://devfeed.tech/sources/finn-no.md>)

Topics: [Machine learning](<https://devfeed.tech/topics/machine-learning.md>), [datasets](<https://devfeed.tech/topics/datasets.md>), [Forms](<https://devfeed.tech/topics/forms.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [data](<https://devfeed.tech/tags/data.md>), [forms](<https://devfeed.tech/tags/forms.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [search](<https://devfeed.tech/tags/search.md>), [supervised-learning](<https://devfeed.tech/tags/supervised-learning.md>), [user](<https://devfeed.tech/tags/user.md>), [using](<https://devfeed.tech/tags/using.md>)

### AI overview

The article explains how FINN småjobber explored automatically guessing job categories from user-submitted titles. Although supervised machine learning was considered, the team used existing indexed job data and normal search to rank likely categories.

### Source excerpt

The problem Making it easy to fill out forms is essential for getting data into our system at FINN småjobber, which is a service to get help with tasks like house cleaning or renovation, where the user submits a job that non-professionals bid on. Submitting a job is done by filling out a form with a title, a short description, and selecting the category the job belongs to. The category hierarchy has two levels: a main category and a subcategory. For example the main category domestic help, has the subcategories cleaning and babysitting. There are 6 main categories and 26 subcategories, and our assumption was that it was a hassle for the user to go through this long list. We wanted to simplify this by guessing the category. Ideally on the given title. The solution Machine learning A typical solution to this kind of problem is to use machine learning, where the goal is to classify job titles into categories. We had a large set of historical data (130 000 registered jobs) where category already was selected by the user. This was a good starting point for a type of machine learning technique called supervised learning. In supervised learning historical data is used as a training set, and results in a classifier that can classify job titles into categories. Delving into the field of machine learning is quite a complex task, and requires both theoretical understanding and knowhow of various software libraries. And in many cases, it requires access to a special machine learning infrastructure. So, as a lean product development team with limited resources we looked for an easier solution. Good old search Search was a sentral part of our service. All the jobs were indexed, and we had all the necessary libraries and infrastructure for this. So, what about using normal search to find the category? A simple search on the title "Cleaning kitchen", gave the following ranked results: Match rank Category 1 Renovation 2 Cleaning 3 Cleaning 4 Renovation 5 Cleaning 6 Cleaning 7 Cleani

## How to make people love your product

DevFeed: [How to make people love your product](<https://devfeed.tech/articles/how-to-make-people-love-your-product-37778.md>)

Original publisher: [Read original article](<https://carlosbecker.com/posts/how-to-make-clients-love-your-product/>)

Author: Carlos Alexandro Becker

Published: 2016-09-27T00:00:00Z

Content type: opinion

Language: en

Sources: [Carlos Becker](<https://devfeed.tech/sources/carlos-becker.md>)

Topics: [Software](<https://devfeed.tech/topics/software.md>), [Security](<https://devfeed.tech/topics/security.md>), [API](<https://devfeed.tech/topics/api.md>), [browser](<https://devfeed.tech/topics/browser.md>), [Documentation](<https://devfeed.tech/topics/documentation.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [browser](<https://devfeed.tech/tags/browser.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [password](<https://devfeed.tech/tags/password.md>), [product](<https://devfeed.tech/tags/product.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [user](<https://devfeed.tech/tags/user.md>)

### AI overview

An opinion article presents four principles for making users love a product: avoid intrusive marketing and dark patterns, provide sensible security practices, preserve standard browser behavior, and minimize unnecessary interaction through clear documentation and an API.

### Source excerpt

I have seen a lot of posts like this subject, but almost all of them were about stuff you should do and almost none of them reflected how I truly feel, how I want a product to be so I can "love" it.

## Designing ClassPass for Android - touchlab

DevFeed: [Designing ClassPass for Android - touchlab](<https://devfeed.tech/articles/designing-classpass-for-android-touchlab-38112.md>)

Original publisher: [Read original article](<https://touchlab.co/2016-2-designing-the-classpass-experience-for-android>)

Published: 2016-02-19T19:56:55Z

Content type: article

Language: en

Sources: [Touchlab | Enterprise Mobile Innovation & Development](<https://devfeed.tech/sources/touchlab-enterprise-mobile-innovation-development.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [App](<https://devfeed.tech/topics/app.md>), [Material Design](<https://devfeed.tech/topics/material-design.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [Toolbar](<https://devfeed.tech/topics/toolbar.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [app](<https://devfeed.tech/tags/app.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [bottom-sheet](<https://devfeed.tech/tags/bottom-sheet.md>), [branding](<https://devfeed.tech/tags/branding.md>), [case-study](<https://devfeed.tech/tags/case-study.md>), [design](<https://devfeed.tech/tags/design.md>), [developers](<https://devfeed.tech/tags/developers.md>), [discovery](<https://devfeed.tech/tags/discovery.md>), [featured](<https://devfeed.tech/tags/featured.md>), [filter](<https://devfeed.tech/tags/filter.md>), [interface](<https://devfeed.tech/tags/interface.md>), [ios](<https://devfeed.tech/tags/ios.md>), [map](<https://devfeed.tech/tags/map.md>), [material-design](<https://devfeed.tech/tags/material-design.md>), [search](<https://devfeed.tech/tags/search.md>), [swipe](<https://devfeed.tech/tags/swipe.md>), [toolbar](<https://devfeed.tech/tags/toolbar.md>), [typography](<https://devfeed.tech/tags/typography.md>), [user](<https://devfeed.tech/tags/user.md>)

### AI overview

touchlab describes its design work adapting the ClassPass iOS experience for Android while preserving the product's branding and functionality. The article explains a unified map-and-results interface using search, filters, a bottom sheet, and an expandable toolbar.

### Source excerpt

In the summer of 2015, touchlab began working with ClassPass, that gives users access to a huge network of fitness facilities for a monthly subscription.

## Security issue on the ReactOS infrastructure

DevFeed: [Security issue on the ReactOS infrastructure](<https://devfeed.tech/articles/security-issue-on-the-reactos-infrastructure-33235.md>)

Original publisher: [Read original article](<https://reactos.org/project-news/security-issue-reactos-infrastructure-2015/>)

Published: 2015-01-21T00:00:00Z

Content type: news

Language: en

Sources: [Front Page on ReactOS Website](<https://devfeed.tech/sources/front-page-on-reactos-website.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [ReactOS](<https://devfeed.tech/topics/reactos.md>), [Security](<https://devfeed.tech/topics/security.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [data](<https://devfeed.tech/topics/data.md>), [Users](<https://devfeed.tech/topics/users.md>), [email](<https://devfeed.tech/topics/email.md>)

Tags: [email](<https://devfeed.tech/tags/email.md>), [free](<https://devfeed.tech/tags/free.md>), [issue](<https://devfeed.tech/tags/issue.md>), [jira](<https://devfeed.tech/tags/jira.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [os](<https://devfeed.tech/tags/os.md>), [password](<https://devfeed.tech/tags/password.md>), [react](<https://devfeed.tech/tags/react.md>), [reactos](<https://devfeed.tech/tags/reactos.md>), [security](<https://devfeed.tech/tags/security.md>), [user](<https://devfeed.tech/tags/user.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [win32](<https://devfeed.tech/tags/win32.md>), [winapi](<https://devfeed.tech/tags/winapi.md>)

### AI overview

ReactOS reported discovering and fixing a vulnerability in its infrastructure that affected the main user database. The database may have exposed usernames, hashed passwords, and email addresses, although ReactOS said it had no evidence confirming or ruling out a leak and recommended that users change their passwords.

### Source excerpt

Dear all, On the 20th of January, we discovered a vulnerability affecting our infrastructure. This vulnerability has been immediately fixed after its discovery. Unfortunately, it was a vulnerability present for years on the infrastructure. This vulnerability was affecting our main users database. This means that our complete user database may have leaked, including user name, password (hashed) and email address. We do not have any evidence that the database actually leaked.

## Workshop with blindfolded lunch

DevFeed: [Workshop with blindfolded lunch](<https://devfeed.tech/articles/workshop-with-blindfolded-lunch-31981.md>)

Original publisher: [Read original article](<https://tech.finn.no2014/11/19/workshop-with-blindfolded-lunch/>)

Author: Lotte Johansen

Published: 2014-11-19T18:00:00Z

Content type: article

Language: en

Sources: [Finn.no](<https://devfeed.tech/sources/finn-no.md>)

Topics: [Accessibility](<https://devfeed.tech/topics/accessibility.md>), [User interface design](<https://devfeed.tech/topics/ui-design.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>)

Tags: [accessibility](<https://devfeed.tech/tags/accessibility.md>), [interaction](<https://devfeed.tech/tags/interaction.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [understand](<https://devfeed.tech/tags/understand.md>), [user](<https://devfeed.tech/tags/user.md>), [workshop](<https://devfeed.tech/tags/workshop.md>)

### AI overview

FINN describes an accessibility workshop held with the Norwegian Association of the Blind and Partially Sighted. Developers, designers, and product owners learned about accessibility requirements and experienced a blindfolded lunch intended to build understanding of users with visual impairments.

### Source excerpt

Workshop with blindfolded lunch in cooperation with The Norwegian Association of the Blind and Partially Sighted (NABP) At FINN a grassroots group of developers and interaction designers launched an initiative to bring up awareness of accessibility. The law of accessibility was introduced July 1st 2014 and m.finn.no is covered by that law because of its major design changes. The Accessibility group in FINN wanted to convey the same message as the NABP; caring for people with disabilities when we build our services, hoping it lead to better user experiences for all. Wednesday November 19th, FINN arranged an accessibility workshop in cooperation with NABP. About 30 developers, designers and product owners attended the keynote by Stein Erik Skotkjerra who is blind and by Kristoffer Lium who is partially sighted. It was an eye-opener for people to see how these two who represented a fairly large group of blind and visually impaired, orients themselves on finn.no. A smaller group of developers and interaction designers attended the whole workshop. We got an introduction to the law of accessibility and the requirements in practice. Stein Erik and Kristoffer both emphesized that the most important is to make sites user friendly; not the law itself. If we think of people with disabilities when we develop finn.no, it will lead to a better site for everyone. Even for those who have a headache one day or are sitting on a bumpy bus while browsing finn.no. The highlight of the day was perhaps "blindfolded lunch". All workshop participants put on ski goggles that were spray painted black so no-one could see anything. Then they were ushered around before being led to a prepared lunch table. The canteen staff from FINN helped to create an exciting lunch with different samples in small cups. It was a challenge to know where the food was, to spread the butter on the bread, and simply to understand what we were eating. At the end of the day the workshop participants tried out various

## Apache: ograniczenie dostępu dla zalogowanych użytkowników z mod\_rewrite i mod\_auth\_basic

DevFeed: [Apache: ograniczenie dostępu dla zalogowanych użytkowników z mod\_rewrite i mod\_auth\_basic](<https://devfeed.tech/articles/apache-ograniczenie-dostepu-dla-zalogowanych-uzytkownikow-z-mod-rewrite-i-mod-auth-basic-27535.md>)

Original publisher: [Read original article](<https://gagor.pro/2012/09/apache-ograniczenie-dostepu-dla-zalogowanych-uzytkownikow-z-mod_rewrite-i-mod_auth_basic/>)

Author: Tom

Published: 2012-09-09T00:00:00Z

Content type: tutorial

Language: pl

Sources: [Tomasz Gągor](<https://devfeed.tech/sources/tomasz-gagor.md>)

Topics: [Mod\_rewrite](<https://devfeed.tech/topics/mod-rewrite.md>), [.NET Framework](<https://devfeed.tech/topics/net-framework.md>)

Tags: [apache](<https://devfeed.tech/tags/apache.md>), [auth](<https://devfeed.tech/tags/auth.md>), [debian](<https://devfeed.tech/tags/debian.md>), [linux](<https://devfeed.tech/tags/linux.md>), [login](<https://devfeed.tech/tags/login.md>), [mod-rewrite](<https://devfeed.tech/tags/mod-rewrite.md>), [rewrite](<https://devfeed.tech/tags/rewrite.md>), [security](<https://devfeed.tech/tags/security.md>), [user](<https://devfeed.tech/tags/user.md>)

### AI overview

This Polish tutorial explains how to use Apache mod_rewrite with mod_auth_basic to redirect authenticated users to directories named after their logins and prevent access to other users' directories. It describes comparing the URI login with the REMOTE_USER value using RewriteRule and RewriteCond backreferences.

### Source excerpt

Niedawno trafiłem na ciekawy problem w mod_rewrite - by przekierowywać użytkowników logujących się jednym z modułów mod_auth_basic do dedykowanych im katalogów, równocześnie blokując dostęp do katalogów innych użytkowników. Nie brzmi to jakoś strasznie ale problem okazał się być całkiem nietrywialnym. Teoretyczne rozwiązanie sprowadzało się do wyszukania loginu użytkownika ze ścieżki URI i porównania z nazwą użytkownika ze zmiennej %{REMOTE_USER} - jeśli wartości się różnią to Forbidden. Ale szybko okazało się że w RewriteCond zmienne z dopasowań można podstawiać tylko w pierwszym parametrze i że o ile można RewriteCond'y połączyć wyrażeniami logicznymi typu AND/OR to nie ma możliwości porównania czy dopasowania z kolejnych RewriteCond'ów są identyczne. Po kilku dniach szperania w dokumentacji i różnych tutorialach udało mi się trafić na jedną wartościową wskazówkę ale tej stronki już nie ma, więc opiszę problem dla potomnych.

## Kathy Sierra: Give your users super-powers

DevFeed: [Kathy Sierra: Give your users super-powers](<https://devfeed.tech/articles/kathy-sierra-give-your-users-super-powers-35295.md>)

Original publisher: [Read original article](<https://darkcoding.net/future-of-web-apps/kathy-sierra-give-your-users-super-powers/>)

Author: Graham King

Published: 2010-07-07T06:15:21Z

Content type: opinion

Language: en

Sources: [Graham King](<https://devfeed.tech/sources/graham-king.md>)

Topics: [Users](<https://devfeed.tech/topics/users.md>), [Software](<https://devfeed.tech/topics/software.md>), [digital](<https://devfeed.tech/topics/digital.md>)

Tags: [advice](<https://devfeed.tech/tags/advice.md>), [business](<https://devfeed.tech/tags/business.md>), [customer](<https://devfeed.tech/tags/customer.md>), [futureofwebapps](<https://devfeed.tech/tags/futureofwebapps.md>), [marketing](<https://devfeed.tech/tags/marketing.md>), [product](<https://devfeed.tech/tags/product.md>), [user](<https://devfeed.tech/tags/user.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

Notes from Kathy Sierra's talk at the Business Of Software conference about designing products and marketing around helping users become better at meaningful activities. The article emphasizes teaching users, creating emotional engagement, supporting them after purchase, and making useful actions easy and obvious.

### Source excerpt

Empowering users to become awesome: The key to great products.