hupden/ projects
blogtools

hupden

Self-hosted services running behind hupden.com.

Projects
5
Posts
8

Recent posts

all posts →
My auth was signing production tokens with an empty key
HMAC is perfectly well defined for a zero-length key. So an unset JWT_SECRET does not crash anything — it signs valid tokens, verifies them, and looks completely healthy. Mine had been doing that in production, and what found it was a startup check I added for a hypothetical.
go · security · jwt
Behavioral fail2ban jails beat signature lists
A jail that matches known-bad paths is always one week behind whatever scanners are trying now. A jail that counts 404s per IP never needs updating. Here is the filter, the two delivery traps that made it silently do nothing, and the blind spot it took me two months to notice.
fail2ban · nginx · security
My agent context file was 60KB and loaded on every session
Every fact I had ever written down about this server was being read into context before a single line of work happened — whether the task was a CSS tweak or a database migration. The fix was not deciding what mattered. Everything in there mattered.
ai-assisted · documentation · self-hosting
JSON Formatter
Paste ugly or escaped JSON and explore it as an interactive tree.
tool · developer
Regex Tester
Test regular expressions against live text with match highlighting, capture groups, and a replace preview.
tool · developer
JWT Inspector
Decode a JWT's header and claims, and flag alg:none or empty-key signing.
tool · security
Secret Generator
Generate a cryptographically strong random secret, locally in your browser.
tool · security
fail2ban Filter Tester
Test a fail2ban failregex against sample log lines and see the host it would ban.
tool · security