Configuring identity-only OAuth requests in Waaseyaa

How Waaseyaa’s oauth-provider package added optional, additive configuration so a consumer that only needs a stable Google or GitHub identity can skip the email lookup, the forced consent prompt, and the offline refresh-token grant.

September 23, 2026 · 5 min · Russell

Host-bound session and CSRF cookies in Waaseyaa

How Waaseyaa’s SessionCookiePolicy enforces the __Host- cookie prefix’s four constraints for both the session cookie and the CSRF double-submit cookie, and rejects misconfiguration at boot instead of failing silently in the browser.

September 19, 2026 · 6 min · Russell

Fixing a metadata collision bug in Waaseyaa's file repository

How Waaseyaa’s LocalFileRepository silently collided metadata for different stream-wrapper URIs that shared a trailing path segment, and the fix that preserves full URI identity plus atomic writes and a reconciliation tool.

September 18, 2026 · 6 min · Russell

Building a conformant stdio MCP server in PHP

The wire-level rules that make a stdio MCP server correct in PHP - one writer to stdout, a bounded read with no natural limit, and a handshake that tells old clients from new ones.

September 15, 2026 · 6 min · Russell

Fixing a cache:clear command that couldn't run and couldn't be trusted

How Waaseyaa’s cache:clear command couldn’t even run in production, and how a hardcoded bin list quietly reported success while clearing the wrong cache entirely.

September 12, 2026 · 6 min · Russell

Fixing a silent message-drop bug in Waaseyaa's queue worker

How Waaseyaa’s queue worker silently acknowledged persistent messages with no matching handler, and the fail-closed fix that routes them through retry and the failed-job repository instead.

September 11, 2026 · 5 min · Russell

Fixing a schema-mutating access check in Waaseyaa's taxonomy package

How Waaseyaa’s taxonomy package let ordinary request traffic ALTER a table to add a foreign key, and the fix that moved that DDL exclusively into coordinated schema sync.

September 9, 2026 · 5 min · Russell

Stop letting a failing audit logger crash requests that already succeeded

Why a throwing audit logger in Waaseyaa’s MCP endpoint could crash a request after its outcome was already decided, and the containment pattern that fixed it.

September 8, 2026 · 5 min · Russell

Stop walking the filesystem in your CI gates — ask git instead

Why Waaseyaa’s CI gate scanners stopped walking the filesystem with a hand-maintained exclusion list and started asking git what’s actually in the repository.

September 7, 2026 · 5 min · Russell

Fixing a silent truncation bug in Waaseyaa's StreamHttpClient

How Waaseyaa’s StreamHttpClient silently turned a truncated, over-limit response body into an HTTP 200, and the fail-closed fix that rejects incomplete bodies instead of guessing.

September 6, 2026 · 5 min · Russell