<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>concurrency on Ikoma's Blog</title><link>https://blog.yusukeikoma.com/tags/concurrency/</link><description>Recent content in concurrency on Ikoma's Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 30 Aug 2026 13:34:18 +0900</lastBuildDate><atom:link href="https://blog.yusukeikoma.com/tags/concurrency/index.xml" rel="self" type="application/rss+xml"/><item><title>Enable Refresh Token Rotation and Parallel Requests Can Log Users Out</title><link>https://blog.yusukeikoma.com/posts/refresh-token-rotation-concurrent-requests/</link><pubDate>Sun, 30 Aug 2026 13:34:18 +0900</pubDate><guid>https://blog.yusukeikoma.com/posts/refresh-token-rotation-concurrent-requests/</guid><description>Refresh token rotation turns a reused token into a theft alarm. A client that fires three requests with an expired access token and refreshes once per 401 presents the same refresh token three times, and trips that alarm on itself. This post breaks a naive client on purpose, fixes it with single-flight refresh and a stale check, and compares the alternatives: a server grace window, request gating, proactive refresh and sender-constrained tokens.</description></item><item><title>One Open Admission While a Start Is Unfinished</title><link>https://blog.yusukeikoma.com/posts/one-open-admission/</link><pubDate>Wed, 12 Aug 2026 10:27:31 +0900</pubDate><guid>https://blog.yusukeikoma.com/posts/one-open-admission/</guid><description>Controlling distributed task starts with one unfinished admission per workspace surface, a fixed destination, and idempotent retries during machine outages.</description></item><item><title>Hardening a Go Daemon and a Python API</title><link>https://blog.yusukeikoma.com/posts/go-daemon-and-python-api-hardening/</link><pubDate>Sat, 01 Aug 2026 14:11:31 +0900</pubDate><guid>https://blog.yusukeikoma.com/posts/go-daemon-and-python-api-hardening/</guid><description>Five techniques from a polyglot codebase: rolling out golangci-lint on existing Go code, running the race detector in CI, bounding subprocess lifetimes, re-registering launchd services without the bootout race, and choosing PostgreSQL row-lock strength around foreign keys.</description></item></channel></rss>