Your API doesn't need to be hacked to become expensive. If a bot can hit an expensive endpoint 50...Your API doesn't need to be hacked to become expensive. If a bot can hit an expensive endpoint 50...
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
Your API doesn't need to be hacked to become expensive.
If a bot can hit an expensive endpoint 50,000 times, you could end up paying for the damage even though your authentication is working perfectly.
I see SaaS teams put a lot of effort into protecting passwords and auth tokens, while overlooking things like rate abuse, brute-force requests, and automated scraping.
For a Laravel + Vue application, these are some of the things I'd put in place:
Rate-limit the expensive stuff
Don't use the same limit for every endpoint.
A search endpoint might allow 60 requests/minute, while an endpoint that generates PDFs or triggers an AI workflow should have a much tighter limit.
Laravel's RateLimiter makes it easy to define limits based on the user, route, subscription, or other conditions.
Redis is a good choice when you're running multiple application servers.
Protect SPA authentication properly
If your Vue frontend talks to Laravel through Axios or Inertia, Laravel Sanctum's cookie-based authentication is usually a better fit than storing JWTs in localStorage.
Sanctum + Laravel's CSRF protection gives you a solid foundation for browser-based authentication without having to build your own token storage system.
Don't return your Eloquent models blindly
This:
return $user;
might work, but it can also expose fields that your frontend never needed.
Use API Resources to explicitly control what gets returned:
return new UserResource($user);
That makes your API response intentional and reduces the chance of accidentally exposing internal fields.
Validate everything coming from the client
Don't trust request payloads just because they came from your own Vue application.
Use Form Requests to handle validation before your business logic runs.
Validate things like:
UUIDs
maximum lengths
allowed values
required fields
numeric ranges
file types and sizes
Your frontend validation is for user experience. Your backend validation is for security and correctness.
The important part is that API security isn't just about authentication.
It's also about controlling what can be called, how often it can be called, what data can be returned, and what the server is allowed to process.
If you're building a Laravel web application, these are things worth thinking about before the API starts getting real traffic.
What’s the secret behind an app that actually feels good to use?
It’s not just the UI.
A beautiful interface can get someone to download an app.
But good engineering is what makes them stay.
When I build an application, I think beyond the screens users can see.
The real work is happening underneath:
⚡ Performance — interactions should feel fast and intentional.
🧠 State management — the app needs to keep data consistent as users move through it.
🏗️ Architecture — the codebase needs structure that can survive new features.
🛡️ Error handling — things will go wrong; the app needs to handle them gracefully.
📱 Responsive UX — the experience needs to work across different screen sizes.
🧪 Testing — don't assume it works because the happy path works.
📊 Monitoring — understand what happens when real users start using it.
That’s the part many people never see.
A user taps a button and thinks:
“That was smooth.”
Behind that single interaction could be API calls, state updates, database operations, validation, loading states, error handling and performance decisions.
That’s why I believe:
A good app isn't just designed. It's engineered.
Modern web performance guidance also emphasizes that loading, responsiveness and efficient resource handling directly affect the user experience.
My goal isn't simply to build something that looks finished.
I want to build applications that behave like real products.
Idea → Architecture → Code → Test → Deploy → Real Users.
What’s one thing that immediately makes you uninstall an app?
Stellar Dungeon — a 2D dungeon crawler built in Godot 4.4 for the Argentina Builder Challenge 2026, with on-chain progression over the Stellar network. I contributed the backend blockchain integration: a Node.js relay and a Rust smart contract (forge_ledger) that log mining, crafting and forging on-chain, with per-player custodial wallets and an offline sync queue.
Tooth-Urgency is an online dental appointment booking platform designed to make accessing dental care simple and convenient. Patients can book scheduled or immediate virtual consultations with dentists based on their needs.
The system allows patients to:
🦷 Book dental appointments online
🚨 Request urgent dental consultations
📅 Select preferred dates and available time slots
👨⚕️ Connect with qualified dentists virtually
💬 Communicate with dentists about their dental concerns
🔔 Receive appointment confirmations and reminders
📋 Manage their appointment history and profiles