Skip to content

Legal

How this site is built

Last updated 9 October 2026.

leffloard.wtf is one Next.js application: these public pages, and behind them an admin that runs my client work. The code is open source.

Stack

  • Next.js 16 with the App Router, React 19 and strict TypeScript.
  • Tailwind CSS 4, and Geist Sans and Geist Mono, served from this site.
  • MongoDB through the official driver, with forward-only migrations.
  • Blog posts in Markdown, sanitised and highlighted with Shiki when they are saved.
  • The moving contour lines on the home page: a small WebGL2 shader that stays off with reduced motion.

Security

  • Admin sign-in with passkeys or a password plus an authenticator code, with progressive lockouts.
  • A Content Security Policy on every page, with a new nonce for scripts on each request.
  • No third-party scripts on public pages, apart from Cloudflare's bot check on forms.

Performance and accessibility

  • Public pages are rendered on each request from an in-memory copy of the published content.
  • Colours meet WCAG AA contrast in both the light and the dark theme.
  • Motion is limited to opacity and position, and disappears when your system asks for reduced motion.

Testing

Unit and integration tests run against a real MongoDB replica set, and browser tests check every page for console errors and Content Security Policy violations.