<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Shawon Barua — Blog</title>
    <link>https://shawonbarua.me/blog</link>
    <description>Notes on building web applications — what worked, what broke, and what I'd do differently.</description>
    <language>en</language>
    <atom:link href="https://shawonbarua.me/blog/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Why your page scrolls sideways on mobile</title>
      <link>https://shawonbarua.me/blog/why-your-page-scrolls-sideways-on-mobile</link>
      <guid isPermaLink="true">https://shawonbarua.me/blog/why-your-page-scrolls-sideways-on-mobile</guid>
      <description>The element that looks broken is almost never the one you have to fix. A short explanation of min-width: auto, and the one-line fix.</description>
      <pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>You cannot hide an API key in frontend code</title>
      <link>https://shawonbarua.me/blog/you-cannot-hide-an-api-key-in-frontend-code</link>
      <guid isPermaLink="true">https://shawonbarua.me/blog/you-cannot-hide-an-api-key-in-frontend-code</guid>
      <description>Not in a constant, not in an env file, not behind a build step. If the browser can use it, the browser can show it — and so can anyone who opens DevTools.</description>
      <pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Your payment webhook will fire twice</title>
      <link>https://shawonbarua.me/blog/your-payment-webhook-will-fire-twice</link>
      <guid isPermaLink="true">https://shawonbarua.me/blog/your-payment-webhook-will-fire-twice</guid>
      <description>Gateways retry when they don't hear a clean answer. If your handler isn't built for that, one payment becomes two accounts, two emails and two deliveries.</description>
      <pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>