Hi, I'm Febin
I build software for healthcare in Kochi, India.
Most of my time goes to a precision-medicine platform for inflammatory bowel disease — it takes genomics and endoscopy data and produces a report a clinician signs. That work made me careful about one particular kind of bug: the kind that throws no error, writes no log line, breaks no test, and is simply wrong until somebody happens to notice.
Almost everything I publish comes out of running into that class of problem somewhere else.
What's here
nexavelos-security-chain — a Spring Security-style filter chain for Express. Path canonicalization, sanitization, CSRF, rate limiting and role-based authorization behind one builder, in a fixed order, instead of eight packages wired together by hand.
Its core idea is that a request matching no authorization rule is refused, not quietly allowed. A route somebody adds next month without a guard fails on its first request instead of sitting open for a year. MIT, published with npm provenance, and honestly still 0.1.x.
bash npm install @nexavelos/security-chain What I work with
Java and Spring Boot on the backend. TypeScript, Next.js and NestJS on the web. Kotlin and Compose for Android. Python where the biology lives.
If you want to help
The security package is new and has no users yet. I would rather someone read the code and tell me what is wrong with it than install it without looking. Issues and pull requests are open, and there is a real security policy behind SECURITY.md.
Reach me at github.com/FebinAugustine or through nexavelos.com.

