Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
YouTube Security VideosGoogle Cloud Tech: Gemini is coming to your city(24.09.2026 um 15:00 Uhr)
AI & KI NachrichtenGoogle’s latest moonshot to put machine learning in space(24.09.2026 um 15:12 Uhr)
Windows Tipps & SecurityPoll: What's your favorite Surface of 2026?(24.09.2026 um 14:58 Uhr)
Sichere ProgrammierungStreaming Materialized Views for Live Read Models (2026)(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungA Day Is Not 86400 Seconds: The DST Bug in Your Date Math(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungSetting up Traefik: reverse proxy with automatic HTTPS(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungA 200 OK response does not prove a secret leak(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungHow hot do you like it?(24.09.2026 um 15:05 Uhr)
YouTube Security VideosGoogle Cloud Tech: Gemini is coming to your city(24.09.2026 um 15:00 Uhr)
AI & KI NachrichtenGoogle’s latest moonshot to put machine learning in space(24.09.2026 um 15:12 Uhr)
Windows Tipps & SecurityPoll: What's your favorite Surface of 2026?(24.09.2026 um 14:58 Uhr)
Sichere ProgrammierungStreaming Materialized Views for Live Read Models (2026)(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungA Day Is Not 86400 Seconds: The DST Bug in Your Date Math(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungSetting up Traefik: reverse proxy with automatic HTTPS(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungA 200 OK response does not prove a secret leak(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungHow hot do you like it?(24.09.2026 um 15:05 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Common mistakes when building a multi-domain photo app (CZ/SK/PL/EN/DE from one codebase)

At Inithouse, a studio shipping a growing portfolio of products in parallel, we run an AI photo animation tool across five country domains from a single codebase. The product turns a static photo into a short living video: zivafotka.cz for…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

At Inithouse, a studio shipping a growing portfolio of products in parallel, we run an AI photo animation tool across five country domains from a single codebase. The product turns a static photo into a short living video: zivafotka.cz for Czech users, zivafotka.sk for Slovak, zywafotka.pl for Polish, alivephoto.online for English, and lebendigfoto.de for German.



Sounds clean on paper. One repo, five builds, five domains. In practice, we walked into every trap the setup could offer. Here are five that cost us the most time.






Mistake 1: One sitemap for all five domains



We started with a single sitemap.xml generated at build time, served identically on every domain. Google indexed the Czech pages fine, then ignored almost everything else. The crawl budget went to whichever domain Google hit first, and hreflang tags pointed in circles because every sitemap referenced every other domain with no clear canonical signal.



What we changed: Each domain now gets its own sitemap listing only its own URLs, with hreflang pointing to the matching pages on sibling domains. Crawl distribution improved within two weeks.






Mistake 2: Hardcoding locale strings in components



Early on, we had Czech strings scattered across React components. Adding Slovak was easy (close enough to copy-paste), but Polish broke our assumptions about string length, and German broke our layout. The codebase turned into a maze of ternary expressions checking window.location.hostname.



What we changed: We extracted all strings into per-locale JSON files and built a thin domain-to-locale resolver that runs at app init. Components just call t('key'). Adding the German domain took a day instead of a week.






Mistake 3: One analytics property, no hostname segmentation



We pointed all five domains at a single GA4 property. The numbers looked great in aggregate. Then we tried to answer "which market converts best?" and realized we had no clean way to split traffic. Hostname as a secondary dimension worked in theory, but half our custom events were missing the hostname parameter entirely.



What we changed: We kept one GA4 property (managing five would be worse), but enforced hostname as a required parameter on every event. We also built a lightweight stats endpoint that segments by domain automatically. We took the same approach at Pet Imagination, our AI pet portrait tool, where the stats API now segments by referral source instead of domain.






Mistake 4: Translating meta descriptions instead of localizing them



We ran the Czech meta descriptions through a translation layer and called it done. The Polish description for the homepage literally said "enliven your photo" in a phrasing no Polish speaker would use for this context. Click-through rates on the Polish domain were 40% lower than Czech for the same ranking positions.



What we changed: We hired native speakers to rewrite (not translate) every meta title and description. Cultural context matters more than literal accuracy. The Polish homepage description now references "rodzinne zdjecia" (family photos) because that turned out to be the dominant use case in Poland, different from the Czech audience that skews toward pet and travel photos.






Mistake 5: Deploying everywhere at once



We shipped to all five domains simultaneously. A layout bug in the German version (long compound words breaking the card grid) went live on a Friday afternoon. By the time we noticed, Google had crawled the broken pages and our Core Web Vitals tanked for lebendigfoto.de.



What we changed: We now deploy to the smallest-traffic domain first (currently Slovak), wait 24 hours, check error logs and Clarity recordings, then roll out to the rest. We apply the same staged-rollout thinking at Audit Vibe Coding, where we test audit report changes on internal projects before pushing them to users.






What we would do differently from day zero



If we started over, we would set up i18n, per-domain sitemaps, and hostname-segmented analytics before writing a single feature component. The multi-domain architecture is worth it for local SEO and trust signals. But the infrastructure tax is real, and paying it upfront is cheaper than retrofitting.



At Inithouse, a lab building many products at once, this was one of our more complex setups. Most products in the portfolio run on a single domain. The five-domain experiment taught us that internationalization is less about translation and more about treating each market as its own product.






Team Inithouse

CTI Threat Relationship Graph2 Knoten / 1 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
SOC Incident Playbook: Remote Code Execution (RCE) Defense
title: Detect Exploitation - Common mistakes when building a multi-domain photo app (CZ/SK/PL/EN/DE from one codebase)
id: 544c00fd-6741-403d-88d4-cf409fb23afb
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-24"
        description = "YARA Signature for "
    strings:
        $str = "Common mistakes when building " ascii wide
    condition:
        any of them
}
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich Common mistakes when building a multi-do.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Common mistakes when building a multi-domain photo app (CZ/SK/PL/EN/DE from one codebase)

Thematisch verwandte Begriffe: Common, mistakes, when, building · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-97179 | A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. T…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick