سرویس Cloudflare میخواد به یه مرجع صدور گواهی عمومی تبدیل بشه.
هدفشون چیه؟ میخوان گواهیهای دیجیتالی بر پایه Merkle Tree Certificates صادر کنن که در برابر حملات کامپیوترهای کوانتومی در آینده مقاوم باشه.
Most .NET developers try to learn everything at once. A skills tree works better, because it tells you what to unlock next instead of handing you a list to drown in.
It all sits on one root: C# fundamentals. Types, LINQ, async and await, collections. Everything above depends on this, so if it feels shaky, this is where your time goes first.
Level 1, Junior. The four nodes that make you employable: web API basics, EF Core CRUD, Git and pull requests, and unit testing with xUnit. Get comfortable shipping a small feature end to end.
Level 2, Mid. Now you go wider: clean or vertical slice architecture, auth with JWT and OAuth, Docker and CI/CD, caching with Redis, and background jobs. Each node unlocks a whole class of problems you can now solve on your own.
Level 3, Architect. Distributed systems, observability, multi-tenancy, system design and trade-offs, AI integration. Less about new syntax, more about knowing what breaks at scale and why.
Three things this tree taught me:
A solid line means "unlock the next thing." Don't jump to distributed systems before you can ship a plain CRUD API.
You don't need every node. Depth in one branch beats a shallow touch of all of them.
And the real jump: juniors collect nodes, seniors collect trade-offs, architects know which nodes NOT to use.
Do this today: find the highest node you can honestly say you've shipped in production. The one sitting right above it is your next focus. Pick that single node and go deep on it this month.
Drop a comment with the node you're on right now. I'm curious where most of you sit, and it might help someone else see they're not as far behind as they think.
What is RBAC (Role-Based Access Control)?
It's one of the most flexible auth policies you can implement.
Here's how it can help with your authorization requirements.
RBAC stands for Role-Based Access Control:
- Roles define high-level policies
- Roles have a set of permissions
- Users belong to roles and inherit permissions
- Permissions decide what a user can or can't do
With standard role-based authorization, I always had a problem with fine-grained auth rules.
Roles are too broad for some policies you'll typically want to enforce.
This is the problem permissions solve.
I can define permissions for specific actions.
It's easy to allow other roles access: you assign the permission to the role.
If you want to learn more about RBAC authorization and how to implement it, start here: https://t.co/pZHWrmxt6f
RBAC makes auth into a flexible, scalable system. Start with permissions. Define what actions users can perform, not what roles they have. It's a much easier way to reason about your app's actions.