Designing Session Cookies That Don't Leak
A field report on building Better-Auth sessions with HTTP-only cookies, rotating tokens, and a cache layer that survives deploys.
- #better-auth
- #cookies
Hey, I'm hocein — a Full-Stack Developer & Linux SysAdmin shipping Next.js/TypeScript apps backed by Go API routes, Prisma + PostgreSQL, and Better-Auth sessions that don't leak.
// try it · type 'help'
// 01 · about
I'm a software developer with a strong passion for the Next.js ecosystem (TypeScript + Tailwind), Go-powered API routes, and database orchestration via Prisma across SQLite, MySQL, and PostgreSQL.
I obsess over auth done right — Better-Auth sessions, HTTP-only cookies, and caching layers that keep REST endpoints fast without leaking state.
// 02 · articles
Half terminal-confessions, half field notes from production.
A field report on building Better-Auth sessions with HTTP-only cookies, rotating tokens, and a cache layer that survives deploys.
Server components, partial prerendering, and the small dance of streaming UI without paying for hydration twice.
A safe playbook for shadow databases, expand-and-contract schemas, and rollbacks you'll actually trust.
// 03 · projects
Tiny Go service that watches git tags, rebuilds container images, and rolls them out behind a REST gateway.
Open-source Prisma extension that streams diffed mutations into an append-only audit table.
Drop-in Better-Auth starter with HTTP-only cookie sessions, edge cache, and Prisma adapters for Postgres & MySQL.
// 04 · uses
Hardware, OS, and software I actually reach for. No affiliate links, just opinions.
// 05 · contact
Got an idea, a server on fire, or just want to nerd out? Drop a message.
// or reach out on