- π Currently contributing to open source infrastructure β auth systems, VCS adapters, SSR runtimes, and developer tooling
- π± Deep-diving into distributed systems, security research, and devtools infrastructure
- π Found and fixed a production MFA security bypass in a major open source BaaS platform
- π¬ Ask me about TypeScript, Node.js, PHP, Go, Docker, Git internals, REST API design
- π« Reach me at jaysomani2016@gmail.com
| Work | What I did |
|---|---|
| GitLab, Gitea, Forgejo, Bitbucket adapters | Built full VCS adapter layer β OAuth2, webhooks (HMAC-SHA256), repository ops, pull requests, normalised output across all providers |
| Unified test architecture | Migrated per-adapter test duplication into a single base class running across all providers β O(n) β O(1) test maintenance |
| Adapter normalisation | Fixed cross-provider inconsistencies so all adapters return uniform {items, total} structure |
| Work | What I did |
|---|---|
| Jaspr SSR runtime | Implemented full SSR runtime for Jaspr (Dart/Flutter web framework) in open-runtimes β reverse-engineered undocumented contract from reference implementations, built health/auth/timings endpoints, verified end-to-end in Docker |
| Work | What I did |
|---|---|
| JWT session null bug | Found production MFA security bypass β JWT-authenticated requests silently skipped factor-count enforcement. Traced through 4 files, proved with failing E2E tests, fix merged |
| deleteSessions current param | Added current bool param to bulk session deletion β JWT-aware session identification, fixed X-Fallback-Cookies regression |
| Session duration param | Added per-login duration param to email/password sessions with validation against project max |
| listX total param | Added total param to 24 list endpoints for consistent API surface |
| Work | What I did |
|---|---|
| Windows PE metadata fix | Fixed entire.exe reporting 0.0.0.0 in Explorer/Get-Command β added goversioninfo build step with CI regression test |
| HTTP redirect security | Fixed POST redirects being silently followed (diverging from vanilla git behavior) β via[0].Method fix covering all 301/302/303/307/308 status codes |
| Warning text accuracy | Fixed misleading warning that blamed a flag users never passed |






