惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
Stack Overflow Blog
Stack Overflow Blog
Latest news
Latest news
T
The Blog of Author Tim Ferriss
D
DataBreaches.Net
C
Check Point Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Security Latest
Security Latest
宝玉的分享
宝玉的分享
S
Schneier on Security
Blog — PlanetScale
Blog — PlanetScale
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Cisco Talos Blog
Cisco Talos Blog
MyScale Blog
MyScale Blog
B
Blog RSS Feed
N
Netflix TechBlog - Medium
P
Privacy & Cybersecurity Law Blog
L
LINUX DO - 热门话题
Apple Machine Learning Research
Apple Machine Learning Research
T
Tenable Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
NISL@THU
NISL@THU
Google DeepMind News
Google DeepMind News
Hacker News: Ask HN
Hacker News: Ask HN
Schneier on Security
Schneier on Security
博客园 - Franky
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
S
Secure Thoughts
T
Threat Research - Cisco Blogs
D
Docker
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
人人都是产品经理
人人都是产品经理
G
GRAHAM CLULEY
Application and Cybersecurity Blog
Application and Cybersecurity Blog
博客园 - 【当耐特】
PCI Perspectives
PCI Perspectives
GbyAI
GbyAI
酷 壳 – CoolShell
酷 壳 – CoolShell
Cyberwarzone
Cyberwarzone
V
Vulnerabilities – Threatpost
F
Fortinet All Blogs
罗磊的独立博客
Engineering at Meta
Engineering at Meta
Y
Y Combinator Blog
SecWiki News
SecWiki News
A
Arctic Wolf
小众软件
小众软件
T
Troy Hunt's Blog
博客园 - 三生石上(FineUI控件)
Know Your Adversary
Know Your Adversary

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
How I Built One
Arish singh · 2026-05-31 · via DEV Community

AI Platform That Turns Your Resume Into Proof that You Can Actually Code so Resume says "React developer." One proves it.


Every developer has been there. You spend 3 hours polishing your resume, listing every framework you've ever opened a tutorial for, and then a recruiter spends 6 seconds scanning it. Interviews test LeetCode algorithms you'll never use on the job. Nobody actually verifies if you can build things.

I got tired of that. So I built One an AI platform that parses your resume, generates a personalized Proof-of-Work assessment from your actual stack, gives you a real-time voice mentor, and builds a 6-month career roadmap from a conversation. All in one workspace.


What I Built

One is a full-stack AI developer career platform. Here's the core loop:

  1. Upload your resume PDF → GPT-4o extracts your real skills (not the company's skills, yours)
  2. Take a Proof-of-Work assessment → 27 auto-generated questions across MCQ, coding, system design, and workflow
  3. Talk to Keri → a voice AI mentor powered by OpenAI Realtime API that knows your scores and stack
  4. Get a 6-month roadmap → generated from your actual conversation with Keri, not a template

Tech stack:

  • Next.js 16 (App Router, Turbopack)
  • Supabase SSR for authentication
  • OpenAI GPT-4o for resume parsing, chat, and roadmap generation
  • OpenAI Realtime API (gpt-4o-realtime-preview) over WebRTC for voice
  • Tailwind CSS v4 + shadcn/ui + Framer Motion
  • Deployed on Vercel

What It Actually Does

  • Parses resume PDFs and extracts only skills the candidate personally used ignores technologies listed in employer descriptions
  • Generates exactly 27 questions: 20 MCQ + 3 coding challenges + 2 system design + 2 workflow questions, all tied to the candidate's actual projects
  • Scores each skill area and renders a visual skill graph
  • Opens a real-time voice session with Keri no audio round-tripping, sub-second response
  • After the conversation, generates a structured 6-month learning roadmap with hours-per-month estimates and an active month marker
  • Fully auth-gated with per-user data isolation no shared state between accounts
  • Supports email signup, Google OAuth, and GitHub OAuth, all without email confirmation friction

Key Features

  • Resume-aware question generation every question references the candidate's specific projects and stack
  • Voice mentor with full context Keri reads your resume skills, test scores, and roadmap before speaking
  • WebRTC voice, not REST — audio goes directly browser → OpenAI, the server is never in the audio path
  • Roadmap from conversation talk to Keri, then one button generates your personalized plan
  • Zero email confirmation server-side admin API creates users with email_confirm: true
  • Per-user localStorage isolation switching accounts clears previous user's data automatically
  • Route protection on every request proxy.ts verifies Supabase session before any page renders
  • Non-resume detection if you upload a hostel form or invoice, One tells you instead of inventing skills

How I Built It

Resume Parsing: Getting GPT-4o to Stop Lying

The naive approach "here's a PDF, what are the skills?" doesn't work. GPT-4o will happily extract every technology mentioned in every job description the candidate ever worked near. That's not the candidate's skill set, that's their employer's stack.

I used OpenAI's Files API to upload the PDF, then hit gpt-4o with a two-step prompt:

const PROMPT = `You are analyzing a document to determine if it is a DEVELOPER/ENGINEER
technical resume and generate a personalized coding assessment.

STEP 1 — Is this a developer resume?
A valid developer resume MUST contain ALL of the following:
- Personal work experience (jobs, internships, freelance) OR personal projects built by the candidate
- At least 3 distinct programming languages, frameworks, libraries, or technical tools used BY THE CANDIDATE

If NOT a valid developer resume, return ONLY:
{ "not_resume": true, "skills": [], "title": "", "questions": [] }

STEP 2 — If valid, return ONLY:
{
  "not_resume": false,
  "skills": ["skill1", "skill2", ...],
  "title": "TopSkill · SecondSkill",
  "questions": [
    { "type": "mcq", "skill": "React", "q": "...", "opts": [...], "a": 0 },
    { "type": "coding", "skill": "JavaScript", "q": "...", "answer": "..." },
    { "type": "system-design", "skill": "System Design", "q": "...", "answer": "..." },
    { "type": "workflow", "skill": "Architecture", "q": "...", "answer": "..." }
  ]
}`;

Step 1 is a gate. If the document doesn't have personal work experience AND 3+ personal skills, it short-circuits and never generates questions. Step 2 has an explicit instruction to extract only skills the candidate personally used.

Then I added a server-side guard on top of the model's own judgment:

// Treat as not-a-resume if: model flagged it, too few skills, or no questions generated
if (parsed.not_resume || skills.length < 3 || questions.length < 5) {
  return NextResponse.json({ not_resume: true, skills: [], title: "", questions: [] });
}

The model can lie. The guard catches it.

One more gotcha: OpenAI's response_format: { type: "json_object" } throws a 400 if the word "json" doesn't appear anywhere in your messages. Took me longer than I want to admit to figure that one out.


Voice AI: WebRTC in Next.js Without Losing Your Mind

Keri uses OpenAI's Realtime API for sub-second voice responses. The architecture matters here — you do not want your server in the audio path. That adds latency and cost. The right flow is:

Browser → (SDP offer) → Next.js server → OpenAI /v1/realtime
OpenAI → (SDP answer) → Next.js server → Browser
Browser ←→ OpenAI (direct WebRTC audio, server out of the loop)

The session endpoint creates a short-lived token:

// /api/realtime/session
const res = await fetch("https://api.openai.com/v1/realtime/sessions", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${key}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    model: "gpt-4o-realtime-preview",
    voice: "shimmer",
  }),
});

The SDP endpoint forwards the browser's WebRTC offer to OpenAI and returns the answer:

// /api/realtime/sdp
const sdpOffer = await req.text();

const res = await fetch("https://api.openai.com/v1/realtime?model=gpt-realtime-2", {
  method: "POST",
  body: sdpOffer,
  headers: {
    Authorization: `Bearer ${key}`,
    "Content-Type": "application/sdp",
  },
});

const answerSdp = await res.text();
return new Response(answerSdp, { status: 200, headers: { "Content-Type": "application/sdp" } });

After the SDP handshake, the server is completely out of the audio path. The browser and OpenAI talk directly over WebRTC. That's why the latency is low — there's no proxy in the middle.


Keri's Context: A Mentor Who Knows You

The thing that makes Keri feel different from a generic chatbot is that she has real data about you injected into every conversation:

const ctxLines: string[] = [];

if (context.skills?.length) {
  ctxLines.push(`Resume skills: ${context.skills.join(", ")}`);
}
if (context.skillScores?.length) {
  const sorted = [...context.skillScores].sort((a, b) => b.v - a.v);
  ctxLines.push(
    `PoW test scores: ${sorted.map((s) => `${s.k} ${s.v}%`).join(", ")}`
  );
}
if (context.roadmap?.length) {
  const rm = context.roadmap.map((m) => {
    const tag = m.active ? " ← CURRENT" : m.done ? " [done]" : "";
    return `Month ${m.month} · ${m.title}: ${m.topics.join(", ")}${tag}`;
  }).join("\n");
  ctxLines.push(`6-month roadmap:\n${rm}`);
}

Every message to GPT-4o carries the user's actual resume skills, their exact test scores sorted by performance, and their current roadmap status. When you ask "what should I work on?", Keri doesn't guess — she looks at your lowest score and your next roadmap month and gives you a specific answer.


Auth: Skipping Email Confirmation Without Disabling Security

Supabase's default signup flow sends a confirmation email before the user can log in. That's terrible UX for an assessment tool where you want people in the app immediately.

Supabase used to have a UI toggle for this. They removed it. The workaround is the admin API:

// /api/auth/register
const supabase = createClient(
  process.env.NEXT_PUBLIC_SUPABASE_URL!,
  process.env.SUPABASE_SERVICE_ROLE_KEY!
);

const { data, error } = await supabase.auth.admin.createUser({
  email,
  password,
  email_confirm: true,  // skip verification entirely
  user_metadata: { full_name: name, organization: org ?? "" },
});

The register page calls this server-side endpoint, then immediately signs in the user with signInWithPassword. No email. No waiting. Just in.


Per-User Data Isolation

One stores resume data, test scores, and roadmap state in localStorage. The problem: if user A logs in after user B on the same browser, they'd see B's data.

The fix is a user ID sentinel key:

const storedUserId = localStorage.getItem("one-current-user");

if (storedUserId !== currentUserId) {
  // Different user — clear everything
  const keysToRemove = Object.keys(localStorage).filter((k) => k.startsWith("one-"));
  keysToRemove.forEach((k) => localStorage.removeItem(k));
  localStorage.setItem("one-current-user", currentUserId);
}

And to make sure no React state from the previous user survives, the entire dashboard remounts using a key prop tied to the user ID:

<main key={userId || "anon"}>
  {/* VoiceAgentPage, ChatbotPage, ResumePage all remount on user change */}
</main>

A React key change forces a full unmount → remount cycle. No stale state, no data bleed between accounts.


Route Protection: Zero Flash of Dashboard

The most important UX requirement: unauthenticated users cannot see a single frame of the dashboard. Not even for 200ms.

Next.js 16 with Turbopack uses proxy.ts (not middleware.ts — having both breaks the build with a conflict error). Every request hits this file first:

const { data: { user } } = await supabase.auth.getUser();

if (!user && !isPublic) {
  const url = request.nextUrl.clone();
  url.pathname = "/login";
  url.searchParams.set("next", pathname);
  return NextResponse.redirect(url);
}

getUser() verifies the JWT with Supabase's servers — it's not just reading a cookie, it's an actual session check. If there's no valid session, the redirect happens before Next.js renders a single byte of the page. The authChecked state in the dashboard is a second layer: the component renders a black screen until the client-side session check confirms.


Roadmap Generation From a Conversation

After talking to Keri, one button generates a structured 6-month learning plan. The model gets the full conversation history and produces a typed JSON object:

const ROADMAP_PROMPT = `You are analyzing a mentoring conversation to generate a
personalized 6-month learning roadmap with working hours.

Return ONLY:
{
  "months": [
    {
      "month": 1,
      "title": "Short title (2-4 words)",
      "focus": "One-line focus statement",
      "topics": ["topic1", "topic2", "topic3"],
      "hours": 40,
      "done": false,
      "active": false
    }
  ]
}

Rules:
- Exactly 6 months, current → 6 months ahead
- Tailor to what the user mentioned: stack, goals, struggles
- "active": true for the one month to focus on RIGHT NOW (only one)
- "done": true for skills already mastered`;

The roadmap uses gpt-4o-mini (cheaper, fast enough for structured JSON) with response_format: { type: "json_object" }. The conversation history is passed directly as messages — no summarization, just the full context.


Lessons Learned

The hardest bugs are prompt bugs, not code bugs.
The resume parser would occasionally invent plausible-looking skills for a PDF that was clearly not a resume. A hostel admission form returned "JavaScript, Python, React" because those words appeared somewhere in the document. The fix wasn't adding more validation code — it was restructuring the prompt to evaluate the document type before attempting skill extraction. A two-step prompt is slower but dramatically more accurate.

Next.js 16 Turbopack has quirks that aren't documented yet.
Having both middleware.ts and proxy.ts in the project root causes a hard build error: "Both middleware.ts and proxy.ts detected." The error message is clear enough, but there's almost nothing about this online because the convention is new. When you hit an undocumented framework error, check the framework version first — the answer is almost always a breaking change from a recent release.

WebRTC in a serverless environment means your server does almost nothing.
The intuition is: real-time audio needs a persistent server. In practice, with OpenAI's Realtime API, your server only handles the SDP handshake (two HTTP requests). Everything after that is peer-to-peer. Serverless functions are completely fine for this pattern.

response_format: { type: "json_object" } will silently break if you don't say "json."
OpenAI's API throws a 400 Bad Request with the message 'messages' must contain the word 'json' if you use JSON mode without the word "json" appearing somewhere in your prompt. After a refactor removed that word from my prompt text, the endpoint broke in production with an error I'd never seen before. Add "Return only a JSON object" to every prompt that uses JSON mode — not just to satisfy the API, but as good practice.

Force-push rewrites git history but GitHub's contributor cache is slow.
After rewriting all commits to remove Co-Authored-By trailers and force-pushing, the Contributors panel on GitHub still showed the old co-author for hours. The code was fixed; the cache just hadn't expired. GitHub's contributor computation runs on a delay — nothing to do but wait.


What's Next

One is live at onee-eight.vercel.app. The core loop works end-to-end. What I'm building next:

  • Shareable PoW cards — a public URL with your verified skill scores you can attach to job applications instead of a resume
  • Employer view — companies post a role, One surfaces candidates ranked by actual test performance in that stack
  • Progressive retesting — take the same assessment monthly and track skill growth over time on the skill graph
  • Team assessments — evaluate an entire engineering team and surface collective gaps by skill area

The core insight hasn't changed: resumes are promises. Proof-of-Work is evidence. The goal is to make the evidence the default.


Built with Next.js 16, Supabase, OpenAI GPT-4o, OpenAI Realtime API, Tailwind CSS v4, and shadcn/ui.

— Arish singh