Samuel Santana
Senior Software Engineer based in Salvador, Brazil, building web applications for more than 12 years. I work mostly on the frontend, with Angular and React, and build the backend in Node.js and NestJS when the product calls for it. Below are the technologies I work with, how I look after quality in production, and where you can check each of them.
Technologies
- Frontend: Angular (Signals, RxJS), React, Next.js (App Router), TypeScript in strict mode, micro-frontends with Module Federation, Tailwind CSS, shadcn/ui, TanStack Query and Zustand.
- Backend: Node.js, NestJS, Fastify, REST and WebSocket APIs, PostgreSQL with Prisma and Drizzle, Redis and BullMQ for queues, and authentication with OAuth 2.0, OpenID Connect (Keycloak) and JWT.
- Infrastructure: AWS (Lambda, S3, CloudFront), Vercel, Neon, Docker and GitHub Actions.
- Design: building from Figma, design tokens in the Tailwind theme, and design systems documented in Storybook.
Quality in production
- Automated tests: unit and component tests with Vitest, Testing Library and MSW (Jasmine and Karma in Angular), end-to-end tests with Playwright and Cypress, and integration suites against real Postgres and Redis in CI. On this site, the end-to-end tests run with no backend, and the ones that depend on another origin run in a separate job.
- Accessibility: WCAG as a delivery requirement. In Ninho's design system, Storybook's accessibility addon fails the build on any violation, axe-core checks WCAG 2 A/AA on the real pages during the end-to-end tests, and 44 px touch targets are measured in Chromium as a CI gate.
- Observability: Sentry for production errors, structured logs with pino, and an audit trail. In corporate environments, Dynatrace, Splunk, Grafana and Kibana, plus DORA metrics dashboards for the teams.
- Security: HttpOnly and SameSite cookies, CORS and security headers, OAuth with state, PKCE and no token in the URL, and dependency scanning in the CI pipeline.
Public projects
Code you can read, run and check:
- Ninho: a child health app for vaccines, appointments and developmental milestones. React 19 with strict TypeScript and a Fastify API in Clean Architecture with PostgreSQL and Redis queues with retries and a dead letter queue. The code is public, and so is the design system, with accessibility checked in CI.
- rx-state-bridge: an npm library that bridges RxJS to React, Angular Signals and Vue without the loading, error and success boilerplate.
- This site: Next.js 16 on the frontend and NestJS on the backend, with a micro-frontends demo in Module Federation.
- BolsoVerde: a sales, fees and payouts tracker for small sellers, in production.
How I work
Before any code, I write the specification: the problem, the acceptance criteria, the constraints and what is out of scope. The implementation is checked against it. When a technical decision has real alternatives, I compare them and record in the pull request why one won, along with what was tried and dropped. When a decision depends on performance or on how something behaves in production, I measure before choosing, with the build output, a reproducible benchmark or the production logs.
I work with AI agents inside that method. I split the work into independent fronts and hand each one to a subagent with shared written criteria. Each one returns the evidence of what it did and says what it could not verify. Each project's knowledge lives in documented conventions and in skills, like the one that brings this site up end to end to verify a change. What must always hold becomes a hook or a CI step. Writes to production, merges and deletions stay with me.
The standard is the same for code from any source: strict typing, tests, green CI, and nothing called done without proof. The posts on this blog are where those measurements are recorded.
Contact
- LinkedIn: linkedin.com/in/samuelcsantana
- GitHub: github.com/samuelcsantana
- Email: samuel.ssa89@gmail.com
Privacy
This site measures how its pages are used with Pyxis, an open-source usage analytics tool I maintain. It sets no cookies, stores no IP address and no identifier that outlives the tab, and records only the page viewed, where the visit came from, the language, the country, the kind of device and browser, how far an article was read, and clicks on the page's own links and buttons. Signing in to comment keeps you anonymous in the measurement. The site honours the browser's "do not track" signal (GPC and DNT), the switch in the footer turns the measurement off in this browser, and events are deleted after 13 months.