<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Mohammed Sinan · Blog</title><description>Full-Stack Software Engineer with 5+ years of experience building and operating production SaaS products and high-traffic web platforms with TypeScript, Node.js, NestJS, React, and Next.js.</description><link>https://m-sinan.netlify.app/</link><item><title>Why Multi-Tenant APIs Should Scope Ownership Through Headers, Not Request Bodies</title><link>https://m-sinan.netlify.app/blog/multi-tenant-ownership-headers/</link><guid isPermaLink="true">https://m-sinan.netlify.app/blog/multi-tenant-ownership-headers/</guid><description>Trusting tenantId or workspaceId from a POST body is an IDOR waiting to happen. When header-based tenancy scoping is the right call — and how to implement it cleanly.</description><pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Eliminating Cache Stampedes on Match Day</title><link>https://m-sinan.netlify.app/blog/cache-stampedes-match-day/</link><guid isPermaLink="true">https://m-sinan.netlify.app/blog/cache-stampedes-match-day/</guid><description>How single-flight deduplication and stale-while-revalidate caching fixed MySQL connection-pool exhaustion during peak fantasy sports traffic.</description><pubDate>Mon, 20 Oct 2025 00:00:00 GMT</pubDate></item><item><title>Building a Resilient AI Audit Pipeline</title><link>https://m-sinan.netlify.app/blog/resilient-ai-audit-pipeline/</link><guid isPermaLink="true">https://m-sinan.netlify.app/blog/resilient-ai-audit-pipeline/</guid><description>How we designed a multi-stage NestJS pipeline with deterministic LLM fallbacks, contract validation, and reproducible audit cycles for a local SEO SaaS.</description><pubDate>Fri, 15 Aug 2025 00:00:00 GMT</pubDate></item></channel></rss>