Vibe coding gets a lot more powerful when you know enough software to refuse the AI’s first “that’s not possible.”
I learned that pretty literally while building what is basically StonkBrokers HR.
I built
placementdesk.xyz unofficially for the
@ClutchMarkets community in a couple days, got it live, and then hit the first real wall: my AI builder didn’t support X OAuth as a native user identity.
The AI said it wasn’t possible. Technical support said it wasn’t possible.
The limitation was real. The conclusion wasn’t.
What I actually needed was simple: X should be the account.
My audience is Web3-native. Asking them to hand over an email just to use the app is basically asking for immediate side-eye. 😒
Log in with X, come back later, same identity, same profile, same wallet links, same applications, same history. No awkward email account bolted underneath it.
The platform couldn’t turn a custom X OAuth flow into one of its native sessions, so instead of accepting a worse product or rebuilding the whole app somewhere else, I built the missing identity layer around it.
The architecture became:
X OAuth 2.0 + PKCE → immutable X user ID → internal Placement Desk Account → server-side AppSession → hashed session token → Secure/HttpOnly/SameSite cookie → backend-authorized reads and writes.
Then came the slightly less fun part: migrating an already-working app without accidentally turning it into a smoking crater. 🔥
So I did it in phases: prove X login could restore the same account, bridge legacy users, then migrate profiles, wallet signing, NFT ownership, applications, positions, admin, bans, session revocation, blocklists, reports, lesson progress, privacy controls, account deactivation, and finally the production login flow.
And because “it works” and “it’s safe” are not the same thing, I spent a mildly unhealthy amount of time attacking it: tampered payloads, cross-account access, replayed wallet challenges, expired challenges, fake admin fields, OAuth state replay, PKCE failures, blocked-user sessions, X-only users with no legacy account, dual-identity edge cases, and one lovely background revalidation path that would have false-closed valid X-only positions because it was still looking for the old user ID.
Very chill. Very no-code. 🫠
The biggest lesson was realizing the AI was answering a narrower question than the product actually needed answered.
“X cannot be a native auth provider here” was true.
“X cannot be the user identity for this product” was not.
That distinction was the whole project.
A lot of my old product management and software development brain came back online during this one: define the real requirement, separate platform constraints from product constraints, design around them, migrate incrementally, test the ugly edge cases, and don’t let a tool limitation become a product limitation.
That’s where I think real development experience takes vibe coding to another level. AI can help you build insanely fast, but understanding application systems and knowing how to problem-solve around constraints is what lets you keep building the thing you actually envisioned.
Anyway,
placementdesk.xyz aka StonkBrokers HR, now has custom X identity infrastructure.
Naturally. 🤝
Also rebuilt the UI with mobile-first in mind, because of course I did. 😉
$STONKBROKER @OxSimpleFarmer