<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Engineering journal — DDLT-Solutions</title><description>Technical notes on real production problems: application security, spatial SQL, RTL i18n, operations.</description><link>https://ddlt-solutions.com/</link><language>en</language><item><title>Assign a point to a zone by spatial query, not by typing</title><link>https://ddlt-solutions.com/en/journal/affectation-zone-requete-spatiale/</link><guid isPermaLink="true">https://ddlt-solutions.com/en/journal/affectation-zone-requete-spatiale/</guid><description>On a map administered by several people, asking a human which zone a point sits in guarantees that one day the map and the database will stop agreeing. The geometry already knows the answer.</description><pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate><category>GIS</category><category>Spatial SQL</category><category>MySQL</category><category>GeoJSON</category></item><item><title>Multi-tenant IDOR: why the tests never catch it</title><link>https://ddlt-solutions.com/en/journal/idor-back-office-multi-tenant/</link><guid isPermaLink="true">https://ddlt-solutions.com/en/journal/idor-back-office-multi-tenant/</guid><description>One manager could read another venue&apos;s unpublished drafts by changing a digit in the URL. The flaw was not in the authorisation code: it was in its absence on a single route, and no test could have caught it.</description><pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate><category>security</category><category>access control</category><category>multi-tenant</category><category>IDOR</category></item></channel></rss>