Сообщения

Анатомия одной попытки: как подключить внешний API к Squarespace и не слить ключи

Анатомия одной попытки: как подключить внешний API к Squarespace и не слить ключи Год назад ко мне пришел владелец нишевого магазина мебели на Squarespace 7.1. Задача звучала невинно: сделать калькулятор доставки прямо в карточке товара, запрашивая точный расчет через API транспортной компании. Штатный верстальщик заказчика предпринял смелую попытку решить задачу «в лоб». Он открыл Code Injection, написал пару десятков строк на чистом JavaScript с обычным fetch() и зашил туда боевой Bearer-токен сервиса. Через четыре дня баланс аккаунта транспортной компании улетел в минус на 92 000 рублей. Скрипт-кидди просто открыли вкладку Network в Chrome DevTools, скопировали ключ и прогнали через него сотни тысяч своих тяжелых запросов. Это классика. Первая попытка подружить закрытый конструктор с внешним миром почти всегда заканчивается либо дырой в безопасности, либо разбитыми надеждами. Две стены Squarespace: CORS и браузерный публичный код Когда создается нестандартная squarespace ap...

How a Single Bubble Workflow Cost My Client $3,400 (And How to Prevent It)

How a Single Bubble Workflow Cost My Client $3,400 (And How to Prevent It) It was 3:14 AM on a Tuesday in April 2023 when my phone started buzzing. It wasn't a standard notification. It was a PagerDuty alert from a real estate platform we had built for a client named Sarah. The alert read: "Bubble Daily WU Limit Exceeded (95%)." I sat up, rubbed my eyes, and opened the Bubble editor. Sarah’s app, which usually cruised along comfortably on a legacy plan for about $115 a month, had consumed 3.2 million Workload Units in less than twelve hours. At the new rate, her projected bill for the month was shaping up to be over $3,400. I was sweating. Sarah was a bootstrapper. A bill like that would kill her startup before it even launched. The culprit? A seemingly innocent backend recursive workflow. It was designed to update a "days on market" counter for her listings. But a junior developer on our team had missed a termination condition. The workflow was running ...

Why Your European Amazon Store is Bleeding Cash (And It's Not the Demand)

Why Your European Amazon Store is Bleeding Cash (And It's Not the Demand) I remember sitting in a drafty warehouse in 2019, staring at 4,000 units of custom-designed silicone baking mats that wouldn't sell. We had killed it on the UK marketplace. We were cocky. So, we figured we would just copy-paste our listing, run the text through a basic translator, and launch on amazon de . We turned on the ads and waited for the cash register to ring. It didn't. We burned €14,200 on PPC in exactly twenty-two days. We got clicks, sure. But our conversion rate sat at a miserable 1.2%. I almost walked away from the continent entirely, convinced that European buyers just didn't want what we were selling. I was wrong. The demand was there. The problem was our listing looked like a cheap, translated scam to a discerning buyer in Munich or Frankfurt. We treated amazon europe like a single, English-speaking monolith. It is not. The Illusion of the English-Speaking European Most...

Как ускорить медленный сайт и пройти Core Web Vitals

Пошаговое руководство по ускорению сайта: от замеров до продакшена Скорость загрузки — это не про «зеленые цифры» в PageSpeed Insights, а про конверсию и SEO. Если ваш сайт грузится дольше 2.5 секунд, вы теряете до 40% трафика. Ниже — мой рабочий алгоритм, который я применяю на проектах. 1. Замеры: где болит? Нельзя оптимизировать то, что нельзя измерить. Забудьте про субъективное «вроде быстрее стало». Инструменты: PageSpeed Insights (для лабораторных данных), Lighthouse (в консоли разработчика), WebPageTest (для waterfall-диаграмм). Что смотрим: LCP (Largest Contentful Paint): Время отрисовки самого большого элемента (цель < 2.5с). CLS (Cumulative Layout Shift): Сдвиги макета (цель < 0.1). INP (Interaction to Next Paint): Отклик на действия пользователя (цель < 200мс). TTFB (Time to First Byte): Время ответа сервера (цель < 0.6с). Ошибка: Оптимизировать сайт только под мобильные или только под десктоп. Всегда смотрите на «медленные» 3G-сети в настр...

Why I Stopped Trusting the OkayCMS Built-in Import for Price Updates

Why I Stopped Trusting the OkayCMS Built-in Import for Price Updates It was a Tuesday morning, 9:14 AM, when my phone started vibrating itself off the desk. It was Andrey, a client running a busy home appliances store on OkayCMS. His site was crawling. Pages were taking twelve seconds to load, and checkout attempts were timing out. Customers were abandoning their carts, and Andrey was losing real money by the minute. The culprit? A cron job we had set up to run the native OkayCMS CSV import script. It was processing a fresh supplier feed of 18,400 items to update prices and stock levels. On paper, it should have worked. In reality, it was eating 100% of the server's CPU and locking the database tables. That was the day I realized that relying on the built-in import tools for high-frequency automated updates is a trap. I had to rebuild the entire integration from scratch. Here is what I learned from that bottleneck, and how we solve it now. The Illusion of the OkayCMS Demo ...

The $14,200 Price Sync Mistake

The $14,200 Price Sync Mistake I have spent the last seven years gluing databases together. If you do this long enough, you develop a nervous twitch every time a client says, "It is just a simple API integration." There is no such thing. Every custom sync engine is a hostage situation waiting to happen, and I learned this the hard way on a rainy Friday night in November. We were managing a catalog of exactly 42,108 SKUs for a consumer electronics retailer. The supplier updated their wholesale prices three times a day. We had built what we thought was a beautiful, state-of-the-art sync engine. At 3:14 AM, the supplier changed their base currency rate. Our engine started loop-updating. It choked. The rate limits kicked in, the connection dropped mid-write, and the database silently fell out of sync. Half the catalog got set to a price of zero. Before we woke up and pulled the plug, customers had ordered thirty-two high-end graphics cards for the price of shipping. That mist...

Как один скрытый символ в прайсе поставщика ломает импорт в PrestaShop

Как один скрытый символ в прайсе поставщика ломает импорт в PrestaShop Я занимаюсь интеграцией каталогов для интернет-магазинов уже больше семи лет. За это время я научился искренне ненавидеть формат CSV. Казалось бы, обычный текстовый файл, где данные разделены запятыми. Что тут можно испортить? Но когда вам на почту падает очередной «грязный» прайс-лист от поставщика автозапчастей или сантехники на 50 000 позиций, а на выходе нужен чистый импорт товаров prestashop csv, начинается настоящая игра на выживание. Вы сталкиваетесь не просто с таблицей. Вы сталкиваетесь с хаосом, который кто-то выгрузил из старой самописной ERP-системы. Я помню тот четверг. Мы запускали крупный магазин климатической техники. Клиент торопился, сезон горел, контекстная реклама была уже оплачена и ждала старта. Поставщик прислал «свежайшую» выгрузку. Я на автомате прогнал её через стандартный скрипт, запустил встроенный импортер PrestaShop и пошел пить кофе. Вернулся через двадцать минут. Сайт лежал. База ...