惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Forbes - Security
Forbes - Security
T
Troy Hunt's Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
H
Hacker News: Front Page
TaoSecurity Blog
TaoSecurity Blog
PCI Perspectives
PCI Perspectives
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
V
Vulnerabilities – Threatpost
博客园 - 【当耐特】
V
Visual Studio Blog
N
News and Events Feed by Topic
Security Archives - TechRepublic
Security Archives - TechRepublic
V
V2EX
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
WordPress大学
WordPress大学
T
Tor Project blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
美团技术团队
P
Proofpoint News Feed
A
Arctic Wolf
C
CERT Recently Published Vulnerability Notes
Last Week in AI
Last Week in AI
T
Tenable Blog
K
Kaspersky official blog
爱范儿
爱范儿
S
Security @ Cisco Blogs
Spread Privacy
Spread Privacy
大猫的无限游戏
大猫的无限游戏
Jina AI
Jina AI
博客园 - 三生石上(FineUI控件)
T
Tailwind CSS Blog
S
SegmentFault 最新的问题
Security Latest
Security Latest
T
The Exploit Database - CXSecurity.com
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Project Zero
Project Zero
W
WeLiveSecurity
L
LINUX DO - 最新话题
Hacker News: Ask HN
Hacker News: Ask HN
阮一峰的网络日志
阮一峰的网络日志
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Cyber Attacks, Cyber Crime and Cyber Security
小众软件
小众软件
Webroot Blog
Webroot Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
Attack and Defense Labs
Attack and Defense Labs

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
CodeApp JS - My Shortcut to Vibe Coding Power Apps
david wyatt · 2026-06-01 · via DEV Community

Code Apps are my current favourite thing about the Power Platform, they follow what I think Microsoft's AI strategy should have been all along "Automate the code underneath, not the UI", as that's what LLMS are good at.

But I found a couple of issues with Code Apps:

  • The CLI requirements is a barrier for some
  • The process is disjointed (e.g. getting connection id from url)
  • Require repo like GitHub (another barrier)
  • React is good for some use cases but overkill for others

So I wanted to create a way to fix these issues, I wanted

  1. A way for most makers to build without adding connectors
  2. To enable Copilot and other Agents to build right first time
  3. No CLI commands needed and a simple workflow
  4. Store the editable code in the platform

Callout, although I dabble in TypeScript I'm stuck in my ways and prefer JavaScript, also I like to build things, so anyone who calls out this probably isn't necessary and the LLM will do all the complex stuff is right

So here was my idea, create a fork of code apps built on top of the power app SDK.

This project has rattled on for a while, and it all came together when Microsoft launched a NPM version of the power platform cli, allowing me to build in that inside my solution instead of an external dependency.

1. CodeApp JS

My plan was to build a conversion process for the SDK into a simple JavaScript (removing the build stage) file that I could then build on top of. The idea was to have these files:

  • power-apps-data.js - the SDK
  • codeapp.js - helper functions, debugger, Dataverse actions, and later date the Flow actions
  • connectors/ - folder with all of the most used connectors converted to JavaScript, they would have easy to use wrappers and built it debugger
  • Index.js* - where all the project JavaScript is
  • Index.html* - where the app UI is
  • power.config.json* - the app config details

*These are standard Code App files that are always required

The default connectors I thought of that covered 90%+ of use cases where:

  • Dataverse
  • Office 365 Outlook
  • Office 365 User
  • Office 365 Groups
  • SharePoint
  • SQL
  • Teams

The next step was to improve how LLMs build Code Apps, as by default they just want to build normal web apps, so I created 2 main areas, agent and skills.

The agent.md file is like a system prompt that you can set in VS Code, it ensures the LLM knows that this is a Code App and to do things like use the SDK instead of simple fetch() functions. The skill.md files are for each connector, they ensure the LLM updates the power.config.json file and doesn't make any silly mistakes.

They all started from a foundation and were incremented on with learnings from building apps, the more I built the more learnings I could train the LLM with

This means that out of the box a maker could build a Code App, but they would need to add schemas for datasources to help the LLM and still used one cli command to publish to the Power Platform.

2. Build Setup

At this point I have done 1 and 2, but what about 3 and 4, well this is where I needed to build (my favourite bit 😎).

To make the workflow easy I needed to replace the CLI commands, and that meant a new UI. The approach I decided to go with was, in a strange contradiction to my objective, was to build a CLI.

There were 3 reasons why I decided

First because I could batch/improve the commands and add new ones. Examples include if I wanted to add a new connector I got the command to find the first valid connection and use that (no getting connection id from the url).

The second and most important was because the CLI can be the foundation for any UI.

dependency

So we have the Code App JS files, which are used by the CLI, which is then used by other Apps. That way when I update the files with new connectors or SDK updates it cascades through, and if I update the CLI with new commands (like when the call flow was added), again it cascades down.

Third I just really really wanted to make a CLI.

3. CAP CLI

The CLI is split into a light and full version. The light covers the CLI commands, the full version builds Copilot SDK into it so it can be a fully standalone agent tool.

Light - the CLI commands

cap help

The CLI commands in theory should make the process more streamlined and simplified, these are the commands I created.

CAP auth - signs you into Power Platform
CAP environment - lists all of your environments and lets you select them. After selecting it also updates the power.config.json file
CAP dataverse - inputs dataverse table, adds it to the power.config.json and adds the schema to the config file (deletes or unnecessary files too)
CAP flow - lists all flows for you to select, adds it to the power.config.json and adds the schema to the config file (deletes or unnecessary files too)
CAP deploy - publishes app to environment, it also copies the power.config.json file into the config folder first (you will see why later)
CAP deploy --debugger - turns on debugger so in the app you can see and copy all connector actions (great to passing to LLM to help debugging)
CAP connector - inputs connector, finds first connection id from environment, imports TypeScript code, converts, embeds debugger functionality and moves to the connector folder (deletes or unnecessary files too)

there are more shortcuts to these like CAP environment -- but you get the idea

That's the standard commands from the Power Platform API, but why stop there, so I've added some of my own

CAP setup - copies all of the templated CodeApp JS files into your project folder, asks for name etc to setup power.config.json file
CAP table - allows you (or the LLM) to create Dataverse tables, you input name, publisher and then add as many columns as you need (any type)
CAP import - my favourite, but I need to explain more

CAP import is the key to objective 4. See the best thing about Vanilla JavaScript in CodeApp JS is it does not need a build step (convert from TypeScript to JavaScript), so the code in the Code App is the code you have written. This means in theory you can export the solution, unzip it and see the code you wrote (or Copilot did). The one thing missing is the power.comfig.json file. But if we copy that, and any other import files like the schemas into the dist folder, lets say in a config folder, then we would have everything we need.

And that's what import does, it lists all of our Code Apps in an environment, you select the app, it finds a solution its in and then exports the solution zip. Once it has the solution it unzips it, grabs the code and adds it to your project folder, finally it copies the power.config.json from the dist/config folder to the root.

So now you can use the Power Platform to store your dev code 😎

Full - Copilot

cap cli

The full version has everything the light version has, but also has the Copilot SDK build in, so you don't need vs code or other agent tools, you can use CAP on its own (and again you can build you own agent tool on top of this).

full dependencies

CAP copilot - sign into your GitHub Copilot account
CAP model - view available models and select the one you want
CAP skills - view list of skills and open to see them
CAP instruction - create your own instruction.md file
CAP - open up interaction session, all inputs are prompts sent to the llm, except when you prefix a /, which the falls back to the CLI for commands like CAP deploy
CAP-p - runs a one off prompt to the llm (like Claude-p)
CAP session - view all saved sessions and select one to continue

cap running

deployed app
As you can see it successfully switched to returning in blocks of 10, though as always there is a small bug with loaded total only showing 10 🤦‍♂️

4. How I use it

Lets be honest, although the CLI is cool it is not the best way to build (cough sorry Claud Code), so how do I use it.

Well at the moment I use a VS Code Extension I created based on the CLI.

cap ext
CAP - Code Apps

For me its the perfect blend of Low-Code and AI. It has all the buttons I need to complete actions like adding Dataverse table or deploying (see bottom of the screen)

buttons

And it delegates all of the code writing to the AI (bit like what we do with Power Apps, we interact with buttons, and delegate most of the code to prebuilt code provided by Microsoft developers).

It also has a couple of added benefits

  • Using Copilot in VS code enables additional models like Gemini Pro 3 that are not enabled through Copilot SDK
  • For CLI your admin will have to enable Copilot to use SDK and for you to install the CLI, where as VS Code Ext is normally just one click
  • I'm use to VS Code so I can use it easily.

Here's a demo video of me building an app using it (Im no Youtuber so expect no production costs, and its a little boring so you may want to fast forward lol)

But I am working on an orchestration app, so that all my Code Apps can be found in one place with a nice UI.

5. Have Ago Yourself

For more information of Code Apps check out https://codeappjs.com/ and more information on CAP CLI check out https://codeappjs.com/cap.html.

Its all open source, so if you want to add connectors/features or fix bugs (I'm sure there are a few), please feel free to submit PRs. Likewise if you don't like the JS side of it, but like the commands you can fork it and use any useful bits.


The interesting thing I found about this is that AI gives us something that we never had before, a world of bespoke solutions to our personal developer ways of working. I found myself constantly spinning up new ways to make me more productive, from new bookmarklets, to entire CLIs and libraries, and that for me is super cool 😎


 
😎 Subscribe to David Wyatt