source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
SATURDAY, OCTOBER 10, 2026
  1. 001Hacker NewsOCT · 09English

    Show HN: Tode – Analytics for Figma plugins, which run in a null-origin iframe

    Tode is an analytics platform designed specifically for Figma plugins and widgets, addressing limitations of traditional browser analytics tools by using the Figma plugin API to accurately track users, sessions, and custom actions in sandboxed iframe environments. The SDK supports multiple frameworks (React, Vue, Angular, Svelte, vanilla JS), offers flexible pricing from free to business tiers, and collects minimal user data while providing dashboards with metrics like daily active users, retention, and feature adoption.

    By kolebayev
  2. 002Hacker NewsOCT · 09English

    CVE-2026-23870: A Single Post Freezes Any Next.js Server

    CVE-2026-23870 is a denial-of-service vulnerability in Next.js server actions where an attacker can craft a malicious POST request with thousands of nested form pointers and fields, causing React's request parsing to perform millions of string checks on a single thread, freezing the server for seconds. The vulnerability requires no authentication and can be exploited by extracting the action ID from public HTML or JavaScript files.

    By Simon Koeck
  3. 003Hacker NewsOCT · 08English

    Show HN: Staffcoder, hands-on practice for modern frameworks in a browser IDE

    Staffcoder is a browser-based IDE offering 500+ hands-on coding challenges across 39 learning paths, where developers practice with real frameworks like React, Next.js, Vue, and Django by solving production-like engineering problems rather than abstract puzzles.

    By shashank21j