Back to Overview
04 / 06
PROJECT 04•edge telemetry

Metricon Link Infrastructure

Sub-Millisecond URL Dispatcher & Zero-Cookie Analytics Engine

Live Subdomain DemoView on GitHub
Quick Reviewer Credentials

1-Click instant demo login available on /auth. Password-protected links use "demo123" with brute-force rate limiting.

User: demo@metricon.co (1-Click Sandbox)Pass: demo123 (Protected link PIN)

Technologies & Stack

Next.js 16React 19TypeScriptDrizzle ORMPostgreSQLUpstash RedisWeb Locks API
metricon.parsadevstudio.ir
IDLE
Metricon Link Infrastructure

System Overview & Purpose

Edge-native URL orchestration platform executing device and geolocation routing with zero database I/O latency, powered by Next.js 16 after() runtime telemetry and Web Locks offline resilience.

Core Architecture

Decoupled 307/308 dispatch from background analytics. GDPR-compliant visitor tracking using deterministic salted SHA-256 IP hashing.

Performance Benchmarks

Sub-1ms

Redirect Latency

Zero database wait time for client navigation

Zero-Cookie

Privacy Standard

GDPR-compliant salted SHA-256 IP hashing

SSRF Defense

Security

Private subnet and cloud metadata IP validation

Engineering Challenges & Solutions

Real software roadblocks encountered during production and their architectural resolutions.

01.

Sub-1ms Redirect Ingestion via Next.js 16 after()

The Problem: Synchronous database insertions for geolocation telemetry added 100-250ms of overhead to every redirect.
The Architectural Solution: Decoupled visitor redirection from persistence inside a Server Component page using Next.js 16 after(). Issues immediate HTTP 307 while analytics transactions execute asynchronously.
Sub-1ms Redirect Ingestion via Next.js 16 after() — Source Solutiontypescript
1234567891011// Decoupled redirect pipeline in Server Component page
after(async () => {
  try {
    await db.transaction(async (tx) => {
      await tx.insert(analytics).values({ linkId: link.id, country, referrer, device, ipHash });
      await tx.execute(sql`UPDATE links SET clicks_count = clicks_count + 1 WHERE id = ${link.id}`);
    });
  } catch {}
});

redirect(targetUrl); // Instant client exit with zero database wait-time
02.

Zero-Dependency SSRF Protection for Metadata Scraper

The Problem: Metadata scrapers for OpenGraph previews can expose cloud metadata endpoints (169.254.169.254) and internal RFC 1918 subnets to SSRF attacks.
The Architectural Solution: Engineered a standalone, zero-dependency address validator parsing hostnames, blocking loopback, and evaluating IPv4 octets against private CIDRs (10/8, 172.16/12, 192.168/16) and IPv6 brackets prior to dispatching fetch.
Zero-Dependency SSRF Protection for Metadata Scraper — Source Solutiontypescript
123456789101112131415// Zero-dependency private subnet and loopback isolation
function isSafeUrl(urlString: string): boolean {
  const url = new URL(urlString);
  const hostname = url.hostname.toLowerCase();
  if (['localhost', '127.0.0.1', '[::1]', '0.0.0.0'].includes(hostname)) return false;

  const match = hostname.match(/^(\d{1,3})\.(\d{1,3})\.(\d{1,3})\.(\d{1,3})$/);
  if (match) {
    const [, o1, o2] = match.map(Number);
    if (o1 === 10 || (o1 === 172 && o2 >= 16 && o2 <= 31) || (o1 === 192 && o2 === 168) || (o1 === 169 && o2 === 254)) {
      return false; // Blocks RFC 1918 and AWS link-local metadata
    }
  }
  return !hostname.startsWith('[fc') && !hostname.startsWith('[fd') && !hostname.startsWith('[fe');
}

Interface & System Screens

High-resolution captures of the live interface and management panels.

Metricon Link Infrastructure Screen 1
01
Metricon Link Infrastructure Screen 2
02
Metricon Link Infrastructure Screen 3
03
Metricon Link Infrastructure Screen 4
04
Previous System
Vendora Commerce Engine
Next System
Vita Personal Engine
Back to Overview