Legal
How this site is built
Last updated 9 October 2026.
leffloard.wtf is one Next.js application: these public pages, and behind them an admin that runs my client work. The code is open source.
Stack
- Next.js 16 with the App Router, React 19 and strict TypeScript.
- Tailwind CSS 4, and Geist Sans and Geist Mono, served from this site.
- MongoDB through the official driver, with forward-only migrations.
- Blog posts in Markdown, sanitised and highlighted with Shiki when they are saved.
- The moving contour lines on the home page: a small WebGL2 shader that stays off with reduced motion.
Security
- Admin sign-in with passkeys or a password plus an authenticator code, with progressive lockouts.
- A Content Security Policy on every page, with a new nonce for scripts on each request.
- No third-party scripts on public pages, apart from Cloudflare's bot check on forms.
Performance and accessibility
- Public pages are rendered on each request from an in-memory copy of the published content.
- Colours meet WCAG AA contrast in both the light and the dark theme.
- Motion is limited to opacity and position, and disappears when your system asks for reduced motion.
Testing
Unit and integration tests run against a real MongoDB replica set, and browser tests check every page for console errors and Content Security Policy violations.