Skip to content
View jaysomani's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report jaysomani

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
jaysomani/README.md

1666024203535

Hi πŸ‘‹, I'm Jayesh Somani

Software Engineer & Open Source Contributor from India

Coding

jayesh_s_s

  • πŸ”­ Currently contributing to open source infrastructure β€” auth systems, VCS adapters, SSR runtimes, and developer tooling
  • 🌱 Deep-diving into distributed systems, security research, and devtools infrastructure
  • πŸ” Found and fixed a production MFA security bypass in a major open source BaaS platform
  • πŸ’¬ Ask me about TypeScript, Node.js, PHP, Go, Docker, Git internals, REST API design
  • πŸ“« Reach me at jaysomani2016@gmail.com

πŸ› οΈ Open Source Contributions

VCS Infrastructure

Work What I did
GitLab, Gitea, Forgejo, Bitbucket adapters Built full VCS adapter layer β€” OAuth2, webhooks (HMAC-SHA256), repository ops, pull requests, normalised output across all providers
Unified test architecture Migrated per-adapter test duplication into a single base class running across all providers β€” O(n) β†’ O(1) test maintenance
Adapter normalisation Fixed cross-provider inconsistencies so all adapters return uniform {items, total} structure

Runtime & SSR

Work What I did
Jaspr SSR runtime Implemented full SSR runtime for Jaspr (Dart/Flutter web framework) in open-runtimes β€” reverse-engineered undocumented contract from reference implementations, built health/auth/timings endpoints, verified end-to-end in Docker

Auth & Security

Work What I did
JWT session null bug Found production MFA security bypass β€” JWT-authenticated requests silently skipped factor-count enforcement. Traced through 4 files, proved with failing E2E tests, fix merged
deleteSessions current param Added current bool param to bulk session deletion β€” JWT-aware session identification, fixed X-Fallback-Cookies regression
Session duration param Added per-login duration param to email/password sessions with validation against project max
listX total param Added total param to 24 list endpoints for consistent API surface

Developer Tooling (Go)

Work What I did
Windows PE metadata fix Fixed entire.exe reporting 0.0.0.0 in Explorer/Get-Command β€” added goversioninfo build step with CI regression test
HTTP redirect security Fixed POST redirects being silently followed (diverging from vanilla git behavior) β€” via[0].Method fix covering all 301/302/303/307/308 status codes
Warning text accuracy Fixed misleading warning that blamed a flag users never passed

Connect with me:

jayesh_s_s jayesh somani somani.jayesh


Languages and Tools:

typescript nodejs go php docker git react nextjs mongodb postgresql gcp


jaysomani

Β jaysomani

jaysomani

Popular repositories Loading

  1. firstspot firstspot Public

    FirstSpot an heven for travellers who love to travel all around the world

    CSS 16 54

  2. Blockchain-Based-Decentralized-Cloud-Storage-System Blockchain-Based-Decentralized-Cloud-Storage-System Public

    Decentralized cloud storage system

    JavaScript 9 7

  3. House-of-books House-of-books Public

    Website to help students in the community to get all the books and notes at one click

    CSS

  4. joomla-cms joomla-cms Public

    Forked from joomla/joomla-cms

    Home of the Joomla! Content Management System

    PHP

  5. Joomla-4-Plugin Joomla-4-Plugin Public

    PHP

  6. gsoc21_cookie-manager gsoc21_cookie-manager Public

    Forked from joomla-projects/gsoc21_cookie-manager

    PHP