favicon here hometagsblogmicrobio cvtech cvgpg keys

Part 2: So I am building a fullstack project

#mercado-series #rust #typescript #deno #fresh #fullstack

Soc Virnyl Estela | 2026-02-16 | updated: 2026-02-16T07:03:33Z |reading time: ~2min

Update: I moved the project to codeberg because I don't want my personal projects to exist there except for work related and other open source stuff that aren't mine (with also some exceptions of the exceptions).

Still a work in progress and I am kind of slow when planning.

Restructure§

After doing some cleanup while also doing volunteering over the weekend, I finally decided on the final structure of the project.

Current project structure
.
├── backend
│   ├── Cargo.toml
│   └── src
│       └── main.rs
├── Cargo.lock
├── Cargo.toml
├── crates
│   ├── api
│   │   ├── Cargo.toml
│   │   └── src
│   │       └── lib.rs
│   ├── auth
│   │   ├── Cargo.toml
│   │   └── src
│   │       └── lib.rs
│   ├── database
│   │   ├── Cargo.toml
│   │   └── src
│   │       ├── bin
│   │       │   └── migrations
│   │       │       ├── down
│   │       │       │   └── 0001_users.rs
│   │       │       └── up
│   │       │           └── 0001_users.rs
│   │       ├── core.rs
│   │       ├── lib.rs
│   │       ├── migrations
│   │       │   ├── down
│   │       │   │   ├── mod.rs
│   │       │   │   └── users.rs
│   │       │   ├── mod.rs
│   │       │   └── up
│   │       │       ├── mod.rs
│   │       │       └── users.rs
│   │       ├── models
│   │       │   ├── mod.rs
│   │       │   ├── products.rs
│   │       │   └── users.rs
│   │       ├── prelude.rs
│   │       └── utils
│   │           └── mod.rs
│   └── payments
│       ├── Cargo.toml
│       └── src
│           └── lib.rs
├── frontend
│   ├── assets
│   │   └── styles.css
│   ├── client.ts
│   ├── components
│   │   └── Button.tsx
│   ├── deno.json
│   ├── deno.lock
│   ├── islands
│   │   └── Counter.tsx
│   ├── main.ts
│   ├── README.md
│   ├── routes
│   │   ├── _app.tsx
│   │   ├── api
│   │   │   └── [name].tsx
│   │   └── index.tsx
│   ├── static
│   │   ├── favicon.ico
│   │   └── logo.svg
│   ├── utils.ts
│   └── vite.config.ts
├── justfile
├── LICENCE
└── README.md

28 directories, 43 files

This project structure is still in the works but it is very effective in managing "which is which", especially after I realised that it's more efficient to use [workspace.dependencies] in the virtual root manifest Cargo.toml.

[workspace]
members = [
        "backend",
        "crates/api",
        "crates/auth",
        "crates/database",
        "crates/payments",
]
resolver = "3"

[workspace.dependencies]
serde = { version = "1.0.228", features = ["derive"] }
serde_json = "1.0.149"
anyhow = "1.0.101"
argon2 = { version = "0.5.3", features = ["std"] }
chrono = { version = "0.4.43", features = ["serde"] }
config = "0.15.19"
deadpool-postgres = { version = "0.14.1", features = ["serde"] }
dotenvy = "0.15.7"
terminfo = "0.9.0"
tokio = { version = "1.49.0", features = ["full"] }
tokio-postgres = { version = "0.7.16", features = ["with-uuid-1", "with-serde_json-1", "with-chrono-0_4"] }
tracing = { version = "0.1.44", features = ["release_max_level_debug", "max_level_trace"] }
tracing-subscriber = { version = "0.3.22", features = ["env-filter"] }
uuid = { version = "1.21.0", features = ["serde", "v4"] }
utoipa = "5.4.0"
utoipa-axum = "0.2.0"
utoipa-swagger-ui = { version = "9.0.2", features = ["axum"] }
axum = "0.8.8"
tower-http = { version = "0.6.8", features = ["full"] }

It ensures that I can pin 1 version of the same dependency or dependencies across the workspace members instead of running cargo add not knowing it's a version that contains a breaking change.

On migrations§

I was thinking of using SeaORM for migrations but decided against it because I want to try vanilla before tasting other flavours, especially convenient ones like SeaORM. I was very much enticed to try SeaORM out when I read their documentation.

But for the sake of learning, I made my own migration script or more accurately, migration executables. I was able to do this because I was planning to make the database crate the entry point for where database functions are called, so it's a library and where the migration logic are defined, so it also contains binaries:

[package]
name = "database"
version = "0.1.0"
edition = "2024"

[[bin]]
name = "up_0001_users"
path = "src/bin/migrations/up/0001_users.rs"

[[bin]]
name = "down_0001_users"
path = "src/bin/migrations/down/0001_users.rs"

[dependencies]
anyhow.workspace = true
argon2.workspace = true
chrono.workspace = true
config.workspace = true
deadpool-postgres.workspace = true
dotenvy.workspace = true
serde.workspace = true
serde_json.workspace = true
terminfo.workspace = true
tokio.workspace = true
tokio-postgres.workspace = true
tracing.workspace = true
tracing-subscriber.workspace = true
uuid.workspace = true

Then I created a just recipe for migrate-up and migrate-down to test them out.

migrate-up:
	cargo run --bin up_0001_users

migrate-down:
	cargo run --bin down_0001_users

migrate-up result migrate-down result

This is just a short update. I am still currently thinking on how to structure the api and I was thinking of using tower-http for convenience for middlewares.

Articles from blogs I follow around the net

[WFD 36] the illusion of best practices

software engineering is full of rules that people follow without thinking. most of them are wrong for you.

via Ryana May Que — Writings for DiscussionMarch 09, 2026

Recently

The snow has been tough for my running schedule in February but it's starting to clear and temperatures have started to lift. Yesterday got in a solid 45 miles of cycling, including up to this point near the George Washington Bridge, and back on the Tappan…

via macwright.comMarch 01, 2026

Cryptography Engineering Has An Intrinsic Duty of Care

To understand my point, I need to first explain three different cryptography attack papers / blog posts. I promise this won’t be boring. Three Little Disclosures Misuse-Prone Ciphers For All In a blog post titled Carelessness versus craftsmanship in crypto…

via Dhole MomentsFebruary 25, 2026

What’s That String? That Time a Weird String Revealed a Whole Operation

How it felt to work on this post. Shikanoko Nokonoko Koshitantan is written by Takashi Aoshima and published by Wit Studio. It all started with a slack message from boB Rudis: “Hey, I keep seeing this string. Any ideas?” d2=%3D%3DQXisTKpcCd4RnLsF3ckN3LlR…

via GreyNoise LabsFebruary 24, 2026

Designing Odin's Casting Syntax

Odin;s declaration syntax becomes second nature to everyone who uses the language but I do sometimes get asked ;Why are there two ways to do type conversions?; Enough that I had to make an FAQ entry..The reason that there are two ways to do type conversio…

via gingerBill - ArticlesFebruary 23, 2026

Status update, February 2026

Hi all! Lars has contributed an implementation independent test suite for the scfg configuration file format. This is quite nice for implementors, they get a base test suite for free. I’ve added support for it for libscfg, the C implementation. I’ve spent …

via emersionFebruary 21, 2026

Investigating the SuperNote Notebook Format

I'm a big fan of eink tablets. I read a lot, I write a lot, I prefer handwritten notes, it's a match made in heaven. I've been using a Kindle Scribe for the past several years - I probably used it as much or more than my phone. Recently, I upgraded to a Su…

via Cracking the ShellFebruary 20, 2026

Luxe, ocaml et volupté

Luxe, ocaml et volupté by Clément Delafargue on February 16, 2026 Tagged as: ocaml. After a couple years using rust as my primary language, I’ve got a new job where I’m using a variety of languages (including rust and typescript), but mostly go 1. So…

via Clément Delafargue - RSS feedFebruary 16, 2026

How To Add DRM To Your Backend (easy) [2026 WORKING]

How KineMaster stopped some modded clients from accessing their asset market

via maia blogFebruary 14, 2026

Push comes to shove tools

Your tools are extensions of your skills

via Ishan WritesFebruary 09, 2026

The cults of TDD and GenAI

I’ve gotten a lot of flack throughout my career over my disdain towards test-driven development (TDD). I have met a lot of people who swear by it! And, I have also met a lot of people who insisted that I adopt it, too, often with the implied threat of appe…

via Drew DeVault's blogJanuary 29, 2026

2025 in review

Come along with me as I review the past year. Heh, I often start these kinds of posts right at the start of the year, but it takes a few weeks longer than I ever expect to think them through.1 Two years of being independent After a second year of operati…

via seanmonstarJanuary 27, 2026

The Birthday Paradox, simulated

I'm a fan of simulating counterintuitive statistics. I recently did this with the Monty Hall problem and I really enjoyed how it turned out. A similarly interesting statistical puzzle is the birthday paradox: you only need to get 23 people in a room a room…

via pcloadletterJanuary 23, 2026

Merry Christmas, Ya Filthy Animals (2025)

It’s my last day of writing for the year, so I’m going to try keep this one quick – it was knocked out over three hours, so I hope you can forgive me if it’s a bit clumsier than my usual writing. For some strange reason, one of the few clear memories I hav…

via LudicityDecember 27, 2025

Why are people migrating away from GitHub?

I noticed some people migrating away from GitHub recently. I was curious to understand the rationale. Is it a blip or is it a sign of prolonged exodus?

via Rob O'Leary | BlogDecember 22, 2025

Yep, Passkeys Still Have Problems

It's now late into 2025, and just over a year since I wrote my last post on Passkeys. The prevailing dialogue that I see from thought leaders is "addressing common misconceptions" around Passkeys, the implication being that "you just don't understand it co…

via Firstyear's blog-a-logDecember 17, 2025

Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office

In June, 2025, Shubs Shah and I discovered a vulnerability in the online poker website ClubWPT Gold which would have allowed an attacker to fully access the core back office application that is used for all administrative site functionality.

via Blog | Sam CurryOctober 12, 2025

Testing multiple versions of Python in parallel

Daniel Roy Greenfeld wrote about how to test your code for multiple versions of Python using `uv`. I follow up with a small improvement to the Makefile.

via Technically PersonalJuly 21, 2025

Generated by openring-rs

favicon here hometagsblogmicrobio cvtech cvgpg keys