MONIMEGA
  • Blog
    • Politics
    • Software
    • Technology
    • Business
    • Design
    • Hardware
    • Health
    • Italy
    • Music
    • Sports
    • Strategy
    • World
  • Contatto
  • Galleria
  • Informazioni
  • Servizi
  • Best Black Friday robot lawn mower deals

    Best Black Friday robot lawn mower deals

    November 25, 2025
    Hardware

    The robot lawn mower has gone from an extremely niche product to approaching mainstream acceptance over the past couple of years, especially among homeowners with larg yards to maintain. But much of this growth in sales has to do with prices, as entry-level models have dropped to less than $1,000.

    Since fewer people shop for lawn mowers as winter approaches, manufacturers have been offering significant discounts to spur sales, and Black Friday is putting that effort into overdrive. We’ve even seen one model priced less than $300—that’s about the same price as a push mower!

    That model won’t be suitable for every yard, of course, but we’ve spotted lots of other deals, which we’ve organized below into three groups: Budget, mid-range, and high-end. For each deal, we include the size of lawn the mower is capable of handling, along with the navigation tech it uses: vision, real-time kinetics (RTK), or GPS (read our guide on how robot mowers navigate for more information).

    • Yardcare V100 Robotic Lawn Mower (vision, 0.2 acres) $299.99 at Amazon (40% off)
    • Yardcare M800 Plus (GPS/vision, .5 acres) $592.79 at Amazon (26% off)
    • Mammotion Yuka Mini 500H Robotic Lawn Mower (RTK/vision, 0.12 acres) $649.00 at Amazon (35% off)
    • Segway Navimow i105n (GPS/Vision, .16 acres) $699.00 at Amazon (30% off)
    • Ecovacs Goat O1000 RTK Robot Lawn Mower (RTK, .25 acres) $799.99 at Amazon (20% off)

    My top pick: The $300 Yardcare V100 is one of the lowest prices I’ve seen for a robot lawn mower. That said, I think most people would be best served by the more robust Segway Navimow i105n.

    Black Friday mid-range robot lawn mower deals

    • Segway Navimow i110n (GPS/vision, .25 acres) $909.00 at Amazon (30% off)
    • Mammotion Luba mini AWD 800 (RTK/Vision, .2 acres) $1,199.00 at Amazon (25% off)
    • Mammotion Yuka 2000 (RTK/Vision, .5 acres) $1,299.00 at Amazon (28% off)
    • Eufy E15 Robot Lawn Mower (vision, 0.2 acres) $1,299.99 at Amazon (43% off)
    • Eufy E18 Robot Lawn Mower (vision, 0.3 acres) $1,499.99 at Amazon (42% off)

    My top pick: Of the mid-range robot mowers on sale for Black Friday, the Segway Navimow i110n and the Eufy E15 and E18 are particularly good deals (the only difference between those two Eufy models is the size of their batteries). I’ve personally tested all three mowers and can recommend them without hesitation.

    Black Friday deals on high-end robot lawn mowers

    If you have a large yard, each of these higher-end robot mowers is a great deal.

    • Ecovacs Goat A3000 Dual LiDAR Robot Lawn Mower (vision, 0.75 acres) $2,099.99 at Amazon (30% off)
    • Husqvarna 410iQ Automower Robotic Mower (EPOS/GPS, .5 acre) $2,099.99 at Amazon (30% off)
    • Husqvarna 420iQ Automower Robotic Mower (EPOS/GPS, 1 acre) $2,449.99 at Amazon (30% off)
    • Husqvarna 440iQ Automower Robotic Mower (EPOS/GPS, 2 acres) $3,999.99 at Amazon (30% off)
    • Yarbo Core + Lawnmower $3,999.00 at Amazon (20% off)
    • Yarbo Core + Snowblower + Lawnmower (up to 6 acres) $4,953.00 at Amazon (20% off)

    Yarbo’s offering is unique in that it consists of a motorized core unit to which you can attach separate modules for different tasks. There’s a mower unit, of course, but also a snow blower, a leaf blower, a snow plow blade, and a trailer hitch.

    FAQ


    1.

    When is Black Friday?

    Black Friday officially starts Friday, November 28 (the day after the Thanksgiving holiday in the U.S.). But retailers are increasingly reluctant to wait that long for the shopping event to start, and you can see from the lists above that there are already some great deals to be had. If you see one that’s tempting, you might want to snag it now in case stocks disappear.

    2.

    What is Cyber Monday? And when is it?

    Retailers created Cyber Monday as a shopping holiday to spur online sales immediately after Thanksgiving. Many of the deals offered on Black Friday are carried over to Cyber Monday, but some are exclusive to that day. This year, Cyber Monday will fall on December 1.

    3.

    Which robot lawn mowers does TechHive rate the highest?

    We were one of the first publications to cover the robot lawn mower market in depth. The best mower for your situation will depend on the size and complexity of your yard. Our guide to the best robot lawn mowers names our top picks and includes a comprehensive buyers’ guide to help you determine what you need.

    4.

    Do you need to be an Amazon Prime member to get Black Friday deals?

    Amazon isn’t the only retailer sponsoring Black Friday sales. Everybody is in the game, from Best Buy to Home Depot. Also, this isn’t one of Amazon’s Prime Day sales, so you don’t need to subscribe to Amazon Prime to get the deals Amazon is offering. That said, if you do buy from Amazon, a Prime membership will entitle you to free shipping and access to Amazon Prime Video (including Thursday Night Football), Amazon Music, and Prime Gaming.

    You can sign up for an Amazon Prime 30-day free trial if you want to give it a try.


    Source: PCWorld.

  • Argentina’s Economy Beats Forecasts Despite Midterm Turmoil

    Argentina’s Economy Beats Forecasts Despite Midterm Turmoil

    November 25, 2025
    Business

    Argentina’s economy expanded more than expected in September despite heightened market turmoil brought on by local and national midterm elections.


    Source: Bloomberg Markets.

  • 😳 Is LeBron's most remarkable streak at risk?

    November 25, 2025
    Sports

    IT TOOK ALL the way until midway through the third quarter on Nov. 18 for LeBron James — already the first player ever to suit up for a 23rd season — to make sure he kept another historic streak intact.

    James, standing on the right side of the court by the Crypto.com Arena logo, passed the ball to Luka Doncic, who was positioned on the perimeter to his left. Once James released the ball, Austin Reaves sprung up from the paint to the 3-point line to set a back screen on Utah Jazz forward Lauri Markkanen, who was guarding the Lakers star.

    The action freed James to advance toward the basket to post up the much smaller Keyonte George, receive a pass back from Doncic and score a layup, maintaining history as he did it.

    It was James’ sixth shot of the game, and his third make.

    More importantly, it lifted his point total to 11 and assured his double-digit scoring streak — which he has tended to for 1,294 games spanning nearly 18 years — would continue.

    Meanwhile, James’ season debut in Utah helped him to potentially maintain a far more prestigious — albeit less talked about — streak, one that better encapsulates his sustained greatness.

    But it’s also one that is precariously close to ending, and not necessarily because of any drop-off in James’ play.

    James has been named to an All-NBA team a record 21 straight times, receiving his first selection after his second season.

    There have been four U.S. presidents in that time. He dominates the category so much that he also holds the record for All-NBA First Team nods with 13, which nearly matches his next closest competition for total All-NBA selections in Kareem Abdul-Jabbar, Tim Duncan and Kobe Bryant, who are tied at 15.

    Since James’ first All-NBA team, the award the league sends out to commemorate the honor has changed from a plaque to a small, crystal basketball-shaped trophy, to a bigger, crystal basketball token of achievement. Additionally, the ballot for each team, which used to be comprised of two guards, two forwards and a center, is now determined by the total number of votes players receive, regardless of position.

    He has been named to the All-NBA team for so long that the league, to combat the dwindling fan interest in the regular season due to players missing time because of load management, changed the requirements to earn an All-NBA spot, or any other regular-season award, by needing to play in at least 65 games to be eligible.

    Which presents the biggest challenge for James to maintain this streak this season.

    On Tuesday, against their crosstown rivals the LA Clippers, the Lakers play their 17th game of the season, which means they have exactly 65 games remaining.

    James made his season debut after missing the first 14 games because of sciatica, a nerve issue that affected his lower back and down the right side of his body.

    What that means is this: From now until the Lakers’ regular-season finale on April 12, James can only miss three games to stay eligible for All-NBA.

    And the Lakers have 11 more back-to-backs remaining on the schedule.

    James’ longtime friend and agent, Rich Paul of Klutch Sports, told ESPN that he hasn’t discussed James’ All-NBA prospects for this season.

    However, if it were up to Paul, James would take himself out of the running for it.

    “Look, at 41 years of age, I hope he is not playing back-to-backs,” Paul said. “But at the same time, in order for him to make the All-NBA team and things like that … he can’t miss that many more games.”

    While there have been occasional cases of a team ruling out back-to-backs for a player because of their injury history — the Clippers and Kawhi Leonard and the Philadelphia 76ers and Joel Embiid are recent examples — it’s rarer for a team to do it simply because of age.

    Last month, the Golden State Warriors took back-to-backs off the table for 39-year-old center Al Horford, with coach Steve Kerr announcing matter-of-factly during the preseason that Horford simply wouldn’t play both legs.

    But it’s hard to imagine James acquiescing to a similar arrangement. Last season, after completing a back-to-back by playing 74 minutes against the Minnesota Timberwolves and the Clippers in the middle of his 22nd year in the league, James spoke about his professional philosophy.

    “I’ve always thought in order to be a leader of a team and someone that is relied on, your availability is very key,” James said. “To be available to your teammates. And I know it’s a tough season. There’s tough seasons every single year. And a lot of games hit us. You never know how the schedule is going to fall out. But I try to be available as much as I can.”

    It’s a responsibility, sources with knowledge of his thinking told ESPN, that James takes seriously.

    He came into last season with a stated intention of playing in all 82 games — something he had only done once in his career in 2017-18.

    That goal lasted 23 games. With L.A. entering a soft portion of the schedule in mid-December, James missed two straight games and secured eight days of rest to recover from foot soreness.

    During that time, for what Lakers coach JJ Redick termed “personal reasons,” James was granted an excused absence away from the team.

    Redick voted for the All-NBA teams in 2023-24 when he worked for ESPN, putting James on the third team on his ballot. He recognizes their importance.

    “I mean, historically at least, it’s probably a higher designation than being an All-Star,” Redick said. “I think if you look at Hall of Fame tracking, typically, obviously it’s changing, more and more guys are getting in now, but typically it’s the more All-NBA awards you have, the greater your chances, versus having eight All-Star appearances [for example].

    “There’s still a couple guys that are out that have multiple All-Star appearances that haven’t gotten in, so I think it’s important for that.”

    Redick said in all his offseason conversations with James, James’ desire to keep his All-NBA streak alive “never came up.”

    Still, Redick has his own opinion about any potential pursuit of a 22nd straight All-NBA selection for James though.

    “I don’t think an All-NBA appearance this year is going to make or break his résumé,” Redick said.

    What could enhance James’ résumé, though, would be another championship, bringing his total to five.

    Giving James a night off here and there, from now until mid-April, would help save his legs for what the Lakers hope is a deep playoff run.

    At the same time, if James believes this could be his last season — something that sources close to James have insisted that he remains undecided about — he might feel even more responsibility to suit up for every game on what would then be a retirement tour.

    Redick said that James’ availability night to night would be determined by a group including James, Redick, James’ longtime athletic trainer Mike Mancias and Dr. Leroy Sims, the Lakers’ director of player performance and health.

    For James to play in 65 of the Lakers’ final 68 games would be remarkable enough.

    To play well enough in those games to still be considered one of the 15 best players in the NBA, at 41, would be even more so.


    Source: www.espn.com – TOP.

  • FBI reportedly seeks to interview Democrats involved in video to troops as senator calls out Trump administration ‘intimidation’ – live

    FBI reportedly seeks to interview Democrats involved in video to troops as senator calls out Trump administration ‘intimidation’ – live

    November 25, 2025
    Politics

    Pentagon said it was investigating Arizona senator Mark Kelly for violating military law by appearing in video in which lawmakers told military members to ‘refuse illegal orders’

    Senator Mark Kelly has responded to the Pentagon’s announcement that it is investigating the Arizona lawmaker for possible breaches of military law after he joined five other Democratic members of Congress in a video calling for US troops to refuse illegal orders.

    “I said something that was pretty simple and non controversial, and that was that members of the military should follow the law,” Kelly said in an MS NOW interview with Rachel on Monday. “And in response to that, Donald Trump said I should be executed.”

    Continue reading…


    Source: World news | The Guardian.

  • Alienware Aurora Gaming Desktop Review: Great Value

    Alienware Aurora Gaming Desktop Review: Great Value

    November 25, 2025
    Technology

    have a market. After all, some people want a simpler entry into the world of PC gaming that doesn’t involve tinkering. That’s where a PC like the Alienware Aurora Gaming Desktop comes into play—in theory.

    While Alienware typically addresses the higher-end demographic with its gaming desktops and laptops, the Aurora Gaming Desktop is the company’s most serious attempt yet to offer its gaming goods at a lower price. Overall, I’ve been happy with what you get with the Aurora, especially when I’ve seen sales that dip the price to $1,500.

    Image may contain Electronics
    Photograph: Luke Larsen

    I recently reviewed the Dell Tower Plus, a prebuilt desktop I liked quite a lot. Turns out, the Aurora Gaming Desktop is almost identical to that PC, but with the Alienware branding (Dell owns Alienware). You get a ring of Tron-esque light around the intake fans at the front, as well as the smattering of honeycomb perforations along the glass window in the side panel. And the alien head itself is the power button.

    It’s accurate to say that the Aurora feels like a gamer skin on the Dell Tower Plus, but that’s not a complaint. I found a lot to like about the way Dell balanced ease of use, upgradability, and price—and it translates well enough for gaming hardware. It’s not using fully off-the-shelf parts, but there’s enough here to make specific upgrades well into the future.

    Like the Dell Tower Plus, the Alienware Aurora Gaming Desktop comes in a custom case with an Intel Z890 Alienware motherboard, which has two DIMM slots of memory and two PCIe 5 M.2 slots for SSDs. Even though a standard ATX or Micro-ATX motherboard would fit, swapping in a new one would be difficult due to the use of proprietary connectors. An AMD CPU is a better option for prebuilt desktops like this, as you might be able to upgrade in future generations because AMD supports the same socket in a way that Intel does not. In other words, if you want a new CPU for the Aurora in a few years, you may be stuck.

    Image may contain Computer Hardware Electronics Hardware Car Transportation Vehicle and Computer
    Photograph: Luke Larsen

    But don’t worry—there’s plenty of other things you can upgrade yourself. The graphics card, for example, is easily accessible. Once I removed the plastic brackets for shipping, it couldn’t be easier to remove the graphics card. RAM, M.2 storage, and the Wi-Fi card are also easy to upgrade yourself, too. Meanwhile, there’s a single storage bay for a 3.5-inch SATA drive located in the bottom right corner with connectors already routed for slower and cheaper storage. There’s also one more open spot for a second intake fan that you can add yourself. In general, cable management is tidy.

    Beyond the basics of what’s offered in the Dell Tower Plus, the Aurora adds things like the option for more powerful graphics and an all-in-one liquid cooler. My review unit came sporting the Nvidia RTX 5070, though the options include the RTX 5060 Ti, 5070 Ti, and 5080. The RTX 5090 is reserved for the company’s mega-tower behemoth, the Alienware Area-51. (There isn’t enough room or power in this case to support that massive card.)

    The 120-mm liquid cooling for the CPU only costs an extra $30 to upgrade, also providing two 120-mm fans installed at the top of the case to exhaust out through the top panel. There’s an RGB fan located in the rear for exhaust, and one up front for intake from the front panel. All that said, there’s a lot more potential for better airflow than in the Dell Tower Plus. In all my stress tests, the system maxed out at 82 degrees Celsius. That’s far from the coolest PC I’ve tested, but it’s within the range of acceptable temperatures.

    Image may contain Computer Electronics Pc Laptop Mobile Phone and Phone
    Photograph: Luke Larsen

    Up front, you get access to some handy ports: a headphone jack, three 5-Gbps USB-A ports, and a 10-Gbps USB-C port. These are the USB ports I often find myself using for convenience. The fastest USB you have is in the back, however. You get one 20-Gbps, USB4 port in the rear of the PC, alongside another 10-Gbps USB-C port, two more 5-Gbps USB-A ports, and two more 480-Mbps USB-A ports.

    Don’t ask me why there have to be so many different USB ports and speeds, but suffice to say, it’s important to know which is which. Fortunately, each is labeled with the actual speeds. There’s also an RJ-45 2.5-gigabit Ethernet jack and your typical line in/line out ports. You’ll want to use the HDMI or DisplayPort in the graphics card for displays, especially since CPUs like the Intel Core Ultra 7 265KF don’t come with integrated graphics, like mine.

    A Decent Performer

    Image may contain Electronics and Speaker
    Photograph: Luke Larsen

    My unit came with an RTX 5070, and it costs an extra $250 to jump up to the RTX 5070 Ti, which gets you an extra 4 GB of VRAM. That’s about on par with GPU prices available right now. At the time of writing, the starting $1,299 model comes with the RTX 5060 Ti, as well as 32 GB of RAM, a 1-terabyte M.2 SSD, and a 500-watt power supply. It’s probably worth the $150 upgrade to get the 1,000-watt power supply, so you’re clear to upgrade to a more powerful graphics card.

    It also came with two sticks of Kingston Fury 16-GB RAM and a Wi-Fi 7 card. All that for $1,550 is a really solid deal. There are cheaper ways to get RTX 5070-level performance, such as this iBuyPower system, but the Alienware Aurora is also far from the most expensive either. The Asus ROG G700, for example, is hundreds of dollars more, even when similarly configured. I haven’t tested these yet myself, so I don’t know how equivalent the performance or fan noise is. But the Alienware Aurora Gaming Desktop is a great deal, especially if you catch it on sale.

    The Alienware Aurora Gaming Desktop performs fine enough. It’s about 5 percent behind the typical RTX 5070 scores in 3DMark Steel Nomad, a standard benchmark for measuring gaming PCs. The RTX 5070 is considered primarily a 1080p video card that can occasionally jump up to 1440p, depending on the game. You can see the frame rates in the chart below, all of which were tested at max settings without ray tracing, frame generation, or upscaling. Cyberpunk 2077 and Black Myth: Wukong are both more GPU-intensive, while Marvel Rivals and Monster Hunter Wilds are more bottlenecked by the CPU.

    Game 2560 x 1440 1920 x 1080
    Cyberpunk 2077 108 fps 163 fps
    Black Myth: Wukong 45 fps 58 fps
    Marvel Rivals 70 fps 96 fps
    Monster Hunter Wilds 70 fps 85 fps

    The performance in Cyberpunk 2077, in particular, felt impressive. I was even able to average 71 fps (frames per second) in the Ray Tracing Ultra preset in 1080p without relying on DLSS. It’s really too bad that it couldn’t get Black Myth: Wukong over 60 fps at 1080p, though. It’s a heavy game, but when you spend over $1,500, you hope that you can play modern games at 1080p at smooth frame rates. You can always drop the graphics preset in the game settings or sprinkle in some light DLSS upscaling for better performance. It was also around 5 percent behind our testing of the RTX 5070 Founders Edition on our test bench.

    While performance didn’t blow me away, I was overall impressed by what’s on offer with the Alienware Aurora Gaming Desktop. This isn’t the PC to buy if you want ultimate control over upgrades in the future or even the most powerful gaming desktop. But if you want a pretty computer that you can upgrade the graphics for in the future, it does the job—just make sure to get it with the 1,000-watt power supply.


    Source: Wired.

  • How to Build a Secure Authentication System with JWT and Refresh Tokens

    How to Build a Secure Authentication System with JWT and Refresh Tokens

    November 25, 2025
    Software

    Every app that handles user accounts needs a way to confirm who’s who. That’s what authentication is for, making sure the person using an app is the person they claim to be. But doing this securely is harder than it sounds.

    Traditional methods often rely on server sessions and cookies. Those work, but they don’t always scale well, especially when you’re building APIs or mobile apps that talk to multiple services. This is why JWTs, or JSON Web Tokens, are useful. They’re small, self-contained tokens that can carry user data safely between a client and a server.

    JWTs make it easy to verify users without constantly checking a database – but they also expire fast to reduce risk. To keep users logged in without forcing them to sign in again every few minutes, we use something called a refresh token. It’s a separate, long-lived token that can request new access tokens when the old ones expire.

    In this guide, we’ll walk through how to build a secure authentication system using JWTs and refresh tokens. You’ll learn how to generate tokens, validate them, handle expiry, and keep everything safe from common security threats.

    1. Understanding JWTs (JSON Web Tokens)

    2. Setting Up the Project

    3. How to Implement JWT Authentication

    4. How to Verify JWTs and Protect Routes

    5. Refresh Tokens and Rotation

    6. Conclusion

    Understanding JWTs (JSON Web Tokens)

    A JWT, short for JSON Web Token, is a compact way to share information between a client and a server. It’s often used to prove that a user is who they say they are. The token is created on the server after a user logs in and is then sent back to the client. The client then includes this token with each request, so the server knows who is making the call.

    A JWT has three parts: a header, a payload, and a signature.

    • The header usually tells the system which algorithm was used to sign the token.

    • The payload contains the data, such as the user’s ID or role.

    • The signature is the part that keeps everything secure. It’s created by hashing the header and payload with a secret key.

    Once created, a JWT looks like a long string of random characters separated by dots. When the client sends it back to the server, the server verifies the signature using the same secret key. If it matches, the request is trusted.

    One of the main benefits of JWTs is that they are stateless. The server doesn’t need to store session data. Everything needed to verify the user is already inside the token. This makes them fast and easy to use in modern APIs and microservices.

    JWTs do have a downside: they cannot be revoked easily once issued. If a token is stolen, the attacker can use it until it expires. This is why short token lifetimes matter. It’s also why refresh tokens exist.

    In the next section, we’ll finish the basic JWT setup. After that, we’ll add refresh tokens in “Refresh Tokens and Rotation.” That part shows how to handle expiry without making users log in again.

    Setting Up the Project

    Before writing any code, let’s set up a simple backend where we can build and test our authentication system. For this guide, we’ll use Node.js with Express, since it’s lightweight and easy to follow. You can use any stack later once you understand the flow.

    Prerequisites

    Make sure you have:

    • Node.js and npm installed

    • A text editor (VS Code works great)

    • Basic knowledge of JavaScript and APIs

    1. Initialize the Project

    Create a new folder and open it in your terminal.

    mkdir jwt-auth-demo cd jwt-auth-demo npm init -y 

    This creates a package.json file that will track your dependencies.

    2. Install Dependencies

    You’ll need a few packages to get started:

    • express: the web framework

    • jsonwebtoken: to create and verify tokens

    • bcryptjs: to hash passwords

    • dotenv: to manage environment variables

    Install them all at once like this:

    npm install express jsonwebtoken bcryptjs dotenv 

    If you want auto-reloading while developing, install nodemon as a dev dependency:

    npm install --save-dev nodemon 

    3. Project Structure

    Here’s a clean structure to keep things organized:

    jwt-auth-demo/ │ ├── server.js ├── .env ├── package.json │ ├── config/ │ └── db.js │ ├── middleware/ │ └── auth.js │ ├── routes/ │ └── auth.js │ └── models/ └── user.js 

    4. Basic Express Setup

    In server.js, start with a minimal Express server.

    require('dotenv').config(); const express = require('express'); const app = express(); app.use(express.json()); app.get('/', (req, res) => { res.send('JWT Auth API running'); }); const PORT = process.env.PORT || 5000; app.listen(PORT, () => console.log(`Server running on port ${PORT}`)); 

    You can now run it using:

    node server.js 

    or, if you’re using nodemon:

    npx nodemon server.js 

    If everything is set up correctly, visiting http://localhost:5000 should display “JWT Auth API running”:

    Screenshot of a terminal running nodemon server.js next to a browser window showing the text “JWT Auth API running” at http://localhost:5000, confirming the server started correctly.

    How to Implement JWT Authentication

    Now that your server is up, let’s add real authentication. We’ll start with user registration, password hashing, and login. Each user will get a token after logging in, which they can use to access protected routes.

    1. Set Up the User Model

    We’ll store users in a simple database. For this demo, let’s use MongoDB with Mongoose, since it’s quick to set up and easy to scale later.

    Install the required packages:

    npm install mongoose 

    Then create models/user.js:

    const mongoose = require('mongoose'); const userSchema = new mongoose.Schema({ username: { type: String, required: true, unique: true }, email: { type: String, required: true, unique: true }, password: { type: String, required: true } }); module.exports = mongoose.model('User', userSchema); 

    We store users with a unique email and a hashed password. The database never sees the raw password. Hashing makes stolen data harder to use.

    2. Connect to MongoDB

    Inside config/db.js:

    const mongoose = require('mongoose'); const connectDB = async () => { try { await mongoose.connect(process.env.MONGO_URI); console.log('MongoDB connected'); } catch (err) { console.error(err.message); process.exit(1); } }; module.exports = connectDB; 

    mongoose.connect reads the connection string from .env. If the connection fails, we exit the process so we don’t continue in a broken state.

    Update your server.js to include the connection:

    const connectDB = require('./config/db'); connectDB(); 

    And don’t forget to add your MongoDB URI in the .env file:

    MONGO_URI=mongodb+srv://yourusername:[email protected]/auth JWT_SECRET=your_jwt_secret_key 

    3. Create Registration and Login Routes

    In routes/auth.js:

    const express = require('express'); const bcrypt = require('bcryptjs'); const jwt = require('jsonwebtoken'); const User = require('../models/user'); const router = express.Router(); // Register a new user router.post('/register', async (req, res) => { try { const { username, email, password } = req.body; const existingUser = await User.findOne({ email }); if (existingUser) return res.status(400).json({ message: 'User already exists' }); const hashedPassword = await bcrypt.hash(password, 10); const newUser = new User({ username, email, password: hashedPassword }); await newUser.save(); res.status(201).json({ message: 'User created successfully' }); } catch (err) { res.status(500).json({ message: 'Server error' }); } }); // Login and issue JWT router.post('/login', async (req, res) => { try { const { email, password } = req.body; const user = await User.findOne({ email }); if (!user) return res.status(400).json({ message: 'Invalid credentials' }); const isMatch = await bcrypt.compare(password, user.password); if (!isMatch) return res.status(400).json({ message: 'Invalid credentials' }); const payload = { id: user._id, email: user.email }; const token = jwt.sign(payload, process.env.JWT_SECRET, { expiresIn: '15m' }); res.json({ token }); } catch (err) { res.status(500).json({ message: 'Server error' }); } }); module.exports = router; 

    Add it to your server in server.js:

    const authRoutes = require('./routes/auth'); app.use('/api/auth', authRoutes); 

    4. Test It Out

    You can now test these routes using Postman or Insomnia.

    Send a POST request to /api/auth/register with a JSON body:

    { "username": "demoUser", "email": "[email protected]", "password": "mypassword" } 

    Screenshot of a Postman request sending a POST call to http://localhost:3000/api/auth/register with a JSON body containing a username, email, and password. The response area shows a 201 Created status and the message “User created successfully."

    The register route checks for an existing user by email. It hashes the password with a cost factor of 10 and then returns a 201 on success. We don’t log the password or include it in the response.

    Then log in at /api/auth/login to receive a JWT.

    Screenshot of a Postman request sending a POST call to http://localhost:3000/api/auth/login with a JSON body containing a username, email, and password. The response panel shows a 200 OK status and a JSON object with a generated JWT token.

    The login route finds the user by email and compares the password with bcrypt.compare. If it matches, we sign a token with a small payload: the user ID and email. The JWT_SECRET signs the token so the server can verify it later. The expiresIn: ’15m’ setting keeps the token short-lived to limit risk. The response only includes the token. User data can be fetched from a protected route.

    Once you get the token, copy it, you’ll use it to access protected routes later.

    How to Verify JWTs and Protect Routes

    Now that login returns a token, we should verify it on each request that needs auth. We will write a small middleware that checks the Authorization header, validates the token, and adds the user info to the request.

    1. Create the Auth Middleware

    Create middleware/auth.js:

    const jwt = require('jsonwebtoken'); function auth(req, res, next) { const authHeader = req.headers.authorization || ''; const [scheme, token] = authHeader.split(' '); if (scheme !== 'Bearer' || !token) { return res.status(401).json({ message: 'Missing or invalid Authorization header' }); } try { const decoded = jwt.verify(token, process.env.JWT_SECRET); req.user = { id: decoded.id, email: decoded.email }; next(); } catch (err) { if (err.name === 'TokenExpiredError') { return res.status(401).json({ message: 'Access token expired' }); } return res.status(401).json({ message: 'Invalid token' }); } } module.exports = auth; 

    What it does:

    • Reads the Authorization header.

    • Checks for the Bearer <token> format.

    • Verifies the token with the secret.

    • Attaches a simple user object to req for later use.

    2. Create the Protected Route

    Create a small profile route that returns the current user. Add routes/profile.js:

    const express = require('express'); const auth = require('../middleware/auth'); const User = require('../models/user'); const router = express.Router(); router.get('/me', auth, async (req, res) => { try { const user = await User.findById(req.user.id).select('-password'); if (!user) { return res.status(404).json({ message: 'User not found' }); } res.json({ user }); } catch (err) { res.status(500).json({ message: 'Server error' }); } }); module.exports = router; 

    Wire it in server.js:

    const profileRoutes = require('./routes/profile'); app.use('/api/profile', profileRoutes); 

    Now a GET /api/profile/me call will only work with a valid token.

    3. Handle Token Expiry Clearly

    Short access tokens reduce damage if they leak. We set expiresIn: '15m' during login. When a token expires, the middleware returns a 401 with Access token expired.

    We won’t refresh the token here because refresh requires its own endpoint, storage, and rotation rules. You’ll add that in “Refresh Tokens and Rotation.” For now, the 401 proves that the expiry is enforced.

    4. Testing the Flow

    In this section, we’ll test that the server blocks requests without a valid token and allows requests with a valid token.

    Log in at /api/auth/login and copy the token. Then call /api/profile/me with:

    Authorization: Bearer <paste_token_here> 

    You should see the current user without the password field.

    Screenshot of a Postman GET request to http://localhost:3000/api/profile/me using a valid JWT. The response shows a 200 OK status and returns the user’s _id, username, and email, confirming that the protected route works when a proper token is included.

    Then remove the header or change the token and call again. You should get a 401.

    Next, wait for the token to expire or change expiresIn to a very short value for a quick test. Call again and confirm you get Access token expired.

    Tips for debugging

    • 401 with “Missing or invalid Authorization header” means the header format is wrong. Use Authorization: Bearer <token>.

    • 401 with “Invalid token” means the token string is wrong, signed with the wrong secret, or corrupted.

    • 401 with “Access token expired” means the expiry check works. You will fix the client experience with the refresh endpoint later.

    • If all calls fail, confirm your JWT_SECRET is set in .env and that the server was restarted after changes.

    5. Optional Cookie Support

    You can store tokens in HTTP-only cookies. The browser sends them automatically. Scripts cannot read HTTP-only cookies, which reduces the risk from XSS.

    Install and enable cookies:

    npm install cookie-parser 
    // server.js const cookieParser = require('cookie-parser'); app.use(cookieParser()); 

    Read the access token from a cookie as a fallback:

    // middleware/auth.js const jwt = require('jsonwebtoken'); function auth(req, res, next) { const header = req.headers.authorization || ''; const [scheme, tokenFromHeader] = header.split(' '); const tokenFromCookie = req.cookies?.access_token; const token = scheme === 'Bearer' && tokenFromHeader ? tokenFromHeader : tokenFromCookie; if (!token) return res.status(401).json({ message: 'No token provided' }); try { const decoded = jwt.verify(token, process.env.JWT_SECRET); req.user = { id: decoded.id, email: decoded.email }; next(); } catch (err) { const msg = err.name === 'TokenExpiredError' ? 'Access token expired' : 'Invalid token'; return res.status(401).json({ message: msg }); } } module.exports = auth; 

    How this works:

    • The access token can live in a cookie named access_token.

    • Mark the cookie as httpOnly and secure in production.

    • Set sameSite: 'strict' to reduce CSRF risk.

    • For APIs used by browsers, cookies simplify sending tokens. For SPAs that call many domains, an Authorization header may be simpler.

    In the next section, we’ll use the same cookie approach for the refresh token. That section explains why refresh belongs in a cookie and how rotation blocks replay.

    Refresh Tokens and Rotation

    Access tokens are short-lived and used on every request. They prove the user identity quickly. Refresh tokens live longer and are used only to get new access tokens when the old ones expire. This split keeps day-to-day requests fast and limits the damage if a token leaks.

    We will store the refresh token in an HTTP-only cookie. This reduces exposure to scripts and keeps the flow smooth.

    1. Install and Setup

    We already have cookie-parser. We won’t add anything new for now, but we will use Node’s built-in crypto module to hash the refresh token before storing it. As a reminder, hashing means the raw token is never saved. If the database leaks, attackers cannot use the hashes to log in.

    Create models/refreshToken.js:

    const mongoose = require('mongoose'); const refreshTokenSchema = new mongoose.Schema({ user: { type: mongoose.Schema.Types.ObjectId, ref: 'User', index: true }, tokenHash: { type: String, required: true, unique: true }, jti: { type: String, required: true, index: true }, expiresAt: { type: Date, required: true, index: true }, revokedAt: { type: Date, default: null }, replacedBy: { type: String, default: null }, // new jti when rotated createdAt: { type: Date, default: Date.now }, ip: String, userAgent: String }); module.exports = mongoose.model('RefreshToken', refreshTokenSchema); 

    2. Token Helpers

    Create utils/tokens.js for clean, reusable logic.

    const jwt = require('jsonwebtoken'); const crypto = require('crypto'); const RefreshToken = require('../models/refreshToken'); const ACCESS_TTL = '15m'; const REFRESH_TTL_SEC = 60 * 60 * 24 * 7; // 7 days function hashToken(token) { return crypto.createHash('sha256').update(token).digest('hex'); } function createJti() { return crypto.randomBytes(16).toString('hex'); } function signAccessToken(user) { const payload = { id: user._id.toString(), email: user.email }; return jwt.sign(payload, process.env.JWT_SECRET, { expiresIn: ACCESS_TTL }); } function signRefreshToken(user, jti) { const payload = { id: user._id.toString(), jti }; const token = jwt.sign(payload, process.env.REFRESH_TOKEN_SECRET, { expiresIn: REFRESH_TTL_SEC }); return token; } async function persistRefreshToken({ user, refreshToken, jti, ip, userAgent }) { const tokenHash = hashToken(refreshToken); const expiresAt = new Date(Date.now() + REFRESH_TTL_SEC * 1000); await RefreshToken.create({ user: user._id, tokenHash, jti, expiresAt, ip, userAgent }); } function setRefreshCookie(res, refreshToken) { const isProd = process.env.NODE_ENV === 'production'; res.cookie('refresh_token', refreshToken, { httpOnly: true, secure: isProd, sameSite: 'strict', path: '/api/auth/refresh', maxAge: REFRESH_TTL_SEC * 1000 }); } async function rotateRefreshToken(oldDoc, user, req, res) { // revoke old oldDoc.revokedAt = new Date(); const newJti = createJti(); oldDoc.replacedBy = newJti; await oldDoc.save(); // issue new const newAccess = signAccessToken(user); const newRefresh = signRefreshToken(user, newJti); await persistRefreshToken({ user, refreshToken: newRefresh, jti: newJti, ip: req.ip, userAgent: req.headers['user-agent'] || '' }); setRefreshCookie(res, newRefresh); return { accessToken: newAccess }; } module.exports = { hashToken, createJti, signAccessToken, signRefreshToken, persistRefreshToken, setRefreshCookie, rotateRefreshToken }; 

    In this code,

    • signAccessToken creates a short token with the user ID and email.

    • signRefreshToken creates a long-lived token with a jti value. The jti lets us rotate and track tokens.

    • persistRefreshToken hashes the refresh token and stores metadata like expiry and device info.

    • setRefreshCookie writes the HTTP-only cookie so the browser sends it to the refresh endpoint automatically.

    • rotateRefreshToken revokes the old token, issues a new pair, and saves the new record. Rotation blocks replay if an old refresh token is stolen.

    3. Issue Refresh Token on Login

    Update your routes/auth.js login handler to create and store a refresh token, then set the cookie.

    const express = require('express'); const bcrypt = require('bcryptjs'); const jwt = require('jsonwebtoken'); const User = require('../models/user'); const RefreshToken = require('../models/refreshToken'); const { createJti, signAccessToken, signRefreshToken, persistRefreshToken, setRefreshCookie } = require('../utils/tokens'); const router = express.Router(); router.post('/login', async (req, res) => { try { const { email, password } = req.body; const user = await User.findOne({ email }); if (!user) return res.status(400).json({ message: 'Invalid credentials' }); const isMatch = await bcrypt.compare(password, user.password); if (!isMatch) return res.status(400).json({ message: 'Invalid credentials' }); const accessToken = signAccessToken(user); const jti = createJti(); const refreshToken = signRefreshToken(user, jti); await persistRefreshToken({ user, refreshToken, jti, ip: req.ip, userAgent: req.headers['user-agent'] || '' }); setRefreshCookie(res, refreshToken); res.json({ accessToken }); } catch (err) { res.status(500).json({ message: 'Server error' }); } }); module.exports = router; 

    On login, we issue both tokens. The access token goes to the JSON response. The refresh token goes to an HTTP-only cookie scoped to /api/auth/refresh. This keeps the refresh token away from frontend code while still letting the browser send it to the refresh endpoint.

    4. The Refresh Endpoint

    Create an endpoint that reads the refresh cookie, verifies it, checks the database entry, and rotates it. If all checks pass, it returns a new access token and sets a new refresh cookie.

    Add to routes/auth.js:

    const { hashToken, rotateRefreshToken } = require('../utils/tokens'); router.post('/refresh', async (req, res) => { try { const token = req.cookies?.refresh_token; if (!token) return res.status(401).json({ message: 'No refresh token' }); let decoded; try { decoded = jwt.verify(token, process.env.REFRESH_TOKEN_SECRET); } catch (err) { return res.status(401).json({ message: 'Invalid or expired refresh token' }); } const tokenHash = hashToken(token); const doc = await RefreshToken.findOne({ tokenHash, jti: decoded.jti }).populate('user'); if (!doc) { return res.status(401).json({ message: 'Refresh token not recognized' }); } if (doc.revokedAt) { return res.status(401).json({ message: 'Refresh token revoked' }); } if (doc.expiresAt < new Date()) { return res.status(401).json({ message: 'Refresh token expired' }); } const result = await rotateRefreshToken(doc, doc.user, req, res); return res.json({ accessToken: result.accessToken }); } catch (err) { res.status(500).json({ message: 'Server error' }); } }); 

    The refresh endpoint verifies the cookie, checks the database record, confirms it is not expired or revoked, then rotates it. Rotation sets revokedAt on the old record and creates a new one with a fresh jti. The response returns a new access token and sets a new refresh cookie.

    5. Logout and Revoke

    On logout, revoke the current refresh token and clear the cookie.

    router.post('/logout', async (req, res) => { try { const token = req.cookies?.refresh_token; if (token) { const tokenHash = hashToken(token); const doc = await RefreshToken.findOne({ tokenHash }); if (doc && !doc.revokedAt) { doc.revokedAt = new Date(); await doc.save(); } } res.clearCookie('refresh_token', { path: '/api/auth/refresh' }); res.json({ message: 'Logged out' }); } catch (err) { res.status(500).json({ message: 'Server error' }); } }); 

    Logout revokes the matching refresh token if present and clears the cookie. This ends the session cleanly on the server side and the client side.

    6. Client Flow

    Here is how the browser app should behave:

    • Keep the access token in memory. Do not put it in localStorage.

    • Call protected APIs with the Authorization header or let cookies handle it if you chose the cookie approach for access.

    • If a call fails with Access token expired, call /api/auth/refresh. The browser sends the refresh cookie automatically.

    • Replace the in-memory access token with the new one.

    • Retry the original request.

    • On logout, call /api/auth/logout and clear any local state.

    7. Security Notes

    There are some key steps you can take to make sure everything is secure:

    Separate secrets

    Use a different secret for access and refresh tokens. If the access secret leaks, refresh tokens still use a different key. Set JWT_SECRET and REFRESH_TOKEN_SECRET in .env.

    HTTPS only

    Serve production traffic over HTTPS. Cookies marked secure: true only travel over HTTPS. This protects tokens in transit.

    Rotate on every refresh

    Issue a new refresh token and revoke the old one each time you refresh. Rotation makes a stolen old token useless after the next refresh.

    Hash refresh tokens in the database

    Store a SHA-256 hash, not the raw token. This way a database leak does not give attackers the actual token string.

    Scope and flags for cookies

    Use httpOnly: true, secure: true in production, sameSite: 'strict', and a narrow path such as /api/auth/refresh. These flags reduce XSS and CSRF risk and limit where the cookie is sent.

    Short access TTL and moderate refresh TTL

    Keep access tokens short, such as 15 minutes. Use a refresh lifetime like 7 days. This keeps risk low without annoying users.

    Device awareness

    Store ip and userAgent. If patterns change in a suspicious way, you can revoke or challenge the session.

    Auditing and limits

    Log refresh events and consider rate limits on the refresh endpoint. This helps detect abuse.’

    Add to .env:

    REFRESH_TOKEN_SECRET=your_refresh_secret_key 

    Conclusion

    You now have a working authentication system that uses JWTs and refresh tokens to keep users logged in safely. The access token handles quick verification. The refresh token quietly renews access when it expires. Together, they strike a balance between security and convenience.

    You built user registration, login, protected routes, and a full refresh flow. You also learned how to rotate refresh tokens, store them securely, and handle logout cleanly. Each step adds another layer of safety that keeps your app and users protected.

    From here, you can expand this setup to match your real project. You can add role-based permissions, track user sessions by device, or move the logic into a dedicated authentication service. What matters most is understanding the flow and keeping tokens short-lived and well-guarded.


    Source: freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More.

  • December 2025 Opportunities: Open Calls, Residencies, and Grants for Artists

    December 2025 Opportunities: Open Calls, Residencies, and Grants for Artists

    November 25, 2025
    Design

    December 2025 Opportunities: Open Calls, Residencies, and Grants for Artists

    Rotterdam Photo 2026 Open Call: Echoes of Silence—War in the Artist’s SoulFeatured
    Rotterdam Photo invites photographers worldwide to explore how war and collective trauma resonate in the artist’s inner world. ‘Echoes of Silence’ asks: What happens when artists are not eyewitnesses to conflict but still carry its emotional legacy? How does violence linger in memory—not as an image, but as a feeling, a silence, a sound within? This edition focuses on photographers who use their lens not as a tool for documentation, but as a mirror reflecting the unseen impact of war, displacement, and survival. Selected applicants receive exhibition space at Rotterdam Photo 2026, along with shows in Barcelona, Tampere, and Zurich, networking opportunities, press exposure, and more.
    Deadline: December 1, 2025.

    Fall $1,800 Innovate Grants for Art + PhotoFeatured
    Innovate Grant awards two $1,800 grants each quarter to one visual artist and one photographer. In addition, twelve applicants will receive honorable mentions, be featured on the website, and join a growing community. International artists and photographers working in any medium are eligible.
    Deadline: 11:59 p.m. PST on December 11, 2025.

    HAHA 2026 – Immersive Installation OpportunityFeatured
    Ah Haa School for the Arts is seeking eight to 12 artists, artist collectives, performers, designers, and creative thinkers of all backgrounds and abilities to propose work for its annual fundraiser. The participatory and interactive community event is a massive, building-wide immersive art installation where each space within the Ah Haa Silverjack building is taken over by a different artist. Selected applicants receive a project budget, lodging, and travel expenses.
    Deadline: 11:59 p.m. MST on January 30, 2026.

     

    Open Calls

    Sanctuary Open Call at Decagon Gallery (International)
    Sanctuary is both a place and a feeling: a refuge, a moment of peace, a return to oneself. This open call invites photographers worldwide to interpret this theme through landscapes, interiors, portraits, abstractions, or documentary work. The first-place award is $500 plus an online exhibition, while the second receives $300, and third receives $200. The entry fee is $5.
    Deadline: November 30, 2025.

    $4,000 Artist Grants + Global Exposure: Exhibition, Publication, Sales, and Promotion (International)
    Ready to elevate your art career with artist grants, recognition, and worldwide visibility? Now in its 5th Annual Juried Edition, the Biafarin Awards offers $4,000 CAD in cash grants and over $6,000 CAD in additional prizes, including group and solo exhibitions, magazine publications, and features on Artsy, the world’s largest art collectors’ platform. This international program welcomes visual artists of all styles and backgrounds to submit their artistic creations to earn grants, enhanced exposure, and reach art professionals, collectors, and enthusiasts in more than 150 countries worldwide.
    Deadline: 11:59 p.m. PST on December 1, 2025.

    PeepSpace Open Call for Exhibition Proposals (International)
    PeepSpace is an artist-run contemporary art project space founded in 2020 in Tarrytown, New York. Emerging and established artists, as well as curators, are invited to submit to the 2026 exhibition open call. From this call, one to two selected exhibition proposals will be chosen for a four- to five-week show during the 2026 calendar year. PeepSpace will provide its 300-square-foot gallery, online promotion, curatorial and installation assistance, and regular gallery hours. Proposals may be for solo shows or group exhibitions. There is a pay-what-you-can entry fee on a sliding scale of $20 to $40.
    Deadline: December 1, 2025.

    Nature Photography Contest 2025 (International)
    All About Photo invites entries to its 2025 photo competition around the theme of nature. Winners will receive $1,000 in cash awards, their winning image(s) or full portfolio published in AAP Magazine Vol.54, and extensive press coverage.
    Deadline: December 9, 2025.

    MEGA – 2026: Grants, Exhibition, Publication, Promotion, Sales, Career Boost (International)
    Mega Art Booster 2026 is Biafarin’s free year-end global art initiative, created to help artists worldwide elevate their visibility, reach, and professional momentum. Open to all styles, mediums, and experience levels, this call connects artists to a worldwide audience of collectors, curators, and art enthusiasts through cash grants, art sales, smart international exhibitions, Artsy feature, global publication, and impactful online promotion.
    Deadline: December 15, 2025.

    2026 Beam Camp Project Open Call (International)
    Beam Center in New Hampshire seeks design proposals for an ambitious public artwork that will be brought to life through collaborations between youth, Beam Camp staff, and the selected proposer. Projects will be realized by a community of more than 100 young people at Beam Camp in July 2026. The chosen artist receives a $5,000 award, and the camp team completes the project with a $15,000 budget.
    Deadline: 11:59 p.m. EST on December 29, 2025.

    GLEAM | 2026 Request for Proposals (International)
    Olbrich Botanical Gardens invites proposals for temporary, light-based installations for GLEAM, Art in a New Light, a public art exhibition situated within a 16-acre Midwest landscape or a 10,000-square-foot tropical conservatory. The 2026 exhibition will focus on concepts that present a captivating environment, offer play experiences, and illuminate creatures of all shapes and sizes, real and imaginative. GLEAM will be open for public viewing from August 29 to October 24.
    Deadline: January 7, 2026.

    Evolving Freedoms: Exploring Life, Liberty and the Pursuit of Happiness (U.S.)
    How do we define freedom in the 21st century? This open call is seeking artists whose work reflects on the ever-shifting meaning of freedom in today’s world. Photographers and print-based artists are invited to submit.
    Deadline: January 30, 2026.

    2026 World of WearableArt Competition (International)
    The 2026 Sections for the world’s leading wearable art competition include Kinetic, Metallic, and Bizarre Bra, alongside the annual sections of Aotearoa, Open, and Avant-garde. Designers are encouraged to focus on original storytelling and meticulous construction. Individuals or teams
    consisting of two or three designers are welcome to enter.
    Deadline: February 26, 2026 (international applicants) and April 15, 2026 (New Zealand applicants).

     

    Grants

    CherryArts Emerging Artist Grants (U.S.)
    CherryArts’ Emerging Artist Program is designed for artists at the beginning of their careers with limited experience exhibiting or selling their work. Emerging Artists receive a reduced booth fee of $350 2026 Cherry Creek Arts Festival in Denver, Colorado; a provided tent; workshops and artist mentoring; support for lodging; and a $5,000 grant.
    Deadline: December 1, 2025.

    Grants for Arts Projects for Individuals and Groups (Western Australia)
    Individuals and groups that deliver arts projects are welcome to apply to this program. Individuals must have Australian citizenship or permanent resident status, and groups, partnerships, and individuals informally collaborating on an activity must also be based in Australia. Funding amounts range from AUD$5,000 to $80,000.
    Deadline: 5 p.m. AWST on December 4, 2025.

    Creative Victoria – Touring Victoria Grants (Victoria, Australia)
    This funding opportunity supports Victorian arts and cultural organizations or professional creative practitioners to tour a professional production, performance, exhibition, or program to or from regional and outer-metropolitan Victoria, Australia. Grant amounts range from AUD$10,000 to $150,000.
    Deadline: 3 p.m. AEDT on December 4, 2025.

    Adelaide Arts & Culture Community Grants (Australia)
    The City of Adelaide’s Community Grants Program supports free and affordable community-led initiatives that foster a vibrant, connected, and inclusive city. The program comprises two focus areas: Arts & Culture and Community Impact. Funding amounts range from AUD$5,000 to $20,000.
    Deadline: 3 p.m. ACDT on December 5, 2025.

    John Ruskin Prize (International)
    The John Ruskin Prize is open to entries from artists, designers, and makers from anywhere in the world. The theme of this year is “Patience in Looking, Truth in Making.” The prize welcomes works in all mediums, and the selection panel will shortlist up to 50 artists and select work for inclusion in an exhibition at Trinity Buoy Wharf, London, from January 29 to February 8, 2026. Four winners will receive prizes totaling £9,500. Entry fees range from £20 to £50 depending on age, medium, and number of entries.
    Deadline: 5 p.m. GMT on December 5, 2025.

    Southern Prize and State Fellowships for Visual Arts (Alabama, Florida, Georgia, Kentucky, Louisiana, Mississippi, North Carolina, South Carolina, and Tennessee)
    This state-specific prize of $5,000 is awarded to artists whose work reflects the best of the visual arts in the South. The nine state fellowship recipients will compete for the $25,000 Southern Prize, which will be awarded to the artist whose work demonstrates the highest artistic excellence. A runner-up will be awarded $10,000.
    Deadline: December 10, 2025.

    Prisma Art Prize (International)
    This annual art prize is open to artists working in painting, engraving, and drawing and offers exhibition opportunities and €2,000 in cash awards annually. There is a €34 entry fee.
    Deadline: December 19, 2025.

    Bobby Anspach Studio Foundation Grant Program (International)
    The Bobby Anspach Studios Foundation launches its inaugural grant program to support creatives and researchers whose work deepens dialogue on meditation, psychology, creativity, and collective engagement as vital pathways to harmony and health. The foundation will award two grants of $50,000 and three grants of $8,000.
    Deadline: December 30, 2025.

    The Adolf and Esther Gottlieb Emergency Grant (International)
    This program provides one-time financial assistance to qualified painters, printmakers, and sculptors whose needs resulted from an unforeseen catastrophic incident and who lack the resources to meet that situation. Awardees typically receive $5,000 and up to $15,000.
    Deadline: Rolling.

    Pollock-Krasner Foundation Grant (International)
    The foundation welcomes applications from painters, sculptors, and artists working on paper, including printmakers. Grants are intended for one year and range up to $50,000. The artist’s circumstances determine the size of the grant, and professional exhibition history will be considered.
    Deadline: Rolling.

     

    Residencies, Fellowships, & More

    Bernheim Forest Artist-in-Residence Program (International)
    Established in 1980, this internationally renowned program annually awards visual artists of all media the opportunity to live and create site-specific work inspired by their total immersion experience in the natural environment. Up to four artists are selected, with one residency always dedicated to an artist currently living in Kentucky or Clark and Floyd counties in Southern Indiana, and one residency always dedicated to an artist whose work addresses environmental issues and the climate crisis.
    Deadline: December 1, 2025.

    Prairie Ronde Spring 2026 Residencies (International)
    Prairie Ronde is hosted by The Mill at Vicksburg, a redevelopment project of the former Lee Paper Company mill, in the historic village of Vicksburg, Michigan. Artists from a range of disciplines are provided with a five- to six-week residency to engage with The Mill and its surrounding 80-acre property. The spring residency period runs from March 15 to May 31. Artists receive a $2,000 stipend upon completion of the residency, a $500 travel grant, private housing, and a gallery show. There is a $25 application fee.
    Deadline: December 1, 2025.

    Jan van Eyck Academie 2027 Residency (International)
    The Jan van Eyck is open to a wide array of disciplines and approaches, ranging from material-based to research-driven practices, addressing both urgent global issues and more personal inquiries. The residency runs for 11 months, from January 15 to December 15, 2026. Housing is included, and participants receive a monthly stipend from which accommodation rental is deducted. There is a €78.65 application fee (including VAT), and waivers may be available depending on location.
    Deadline: December 4, 2025.

    Collective Edinburgh Time + Space Program (Scotland)
    Time + Space is Collective’s new open program for early-career artists in Scotland. The program offers two routes designed to suit different levels of experience. Both opportunities combine learning and professional development with a significant exhibition opportunity, enabling artists to develop and sustain their creative practice, to make and present new work, and to engage with Collective audiences.
    Deadline: 5 p.m. GMT on December 14, 2025.

    2026 CatchLight Global Fellowship (International)
    Each year, visual media organization CatchLight Global Fellowship awards $30,000 grants to three innovative storytellers whose work is a tool for information, connection, and transformation in their communities.
    Deadline: December 15, 2025.

    Harvestworks 2026 Artist-in-Residence Program (U.S.)
    Harvestworks’ Artists-in-Residence Program supports contemporary artists working at the intersection of art and technology. Residents will develop and present new projects that explore how technology can deepen our understanding of the world, provoke new ideas, and ignite the imagination. Each artist will receive a $5,000 commission to produce a new work integrating technology, sound, and visual art. Residencies take place at Harvestworks’ Technology, Engineering, Art and Music Lab (T.E.A.M.) in New York City.
    Deadline: 11:59 p.m. EST on December 20, 2025.

    Chicago Artists Coalition 2026 Artist and Curatorial Residency (U.S.)
    The CAC residency is totally without cost to artists and curator participants, during which a cohort is composed of 15 artists paired with five curators. The residency culminates in on-site exhibitions of three artists and one curator. Artists and curators each receive a one-time stipend of $350. There is also a $225 supply budget and 18 hours of preparator time allotted to the installation of the exhibition. Six residents receive free studio space on-site for one year.
    Deadline: 11:59 p.m. CST on December 21, 2025.

    Yaddo Residencies (International)
    Yaddo offers residencies to professional creative artists from all nations and backgrounds working in one or more of the following disciplines: choreography, film, literature, musical composition, painting, performance, photography, printmaking, sculpture, and video. Artists apply individually. Residencies last from two weeks to two months and include room, board, and a studio. There is a $35 application fee.
    Deadline: January 5, 2026.

    Glen Arbor Arts Center 2026 Artist-in-Residence (International)
    The Glen Arbor Arts Center offers several opportunities for artist residencies each year. The purpose of the residency program is to provide visiting artists with a respite from daily responsibilities to enable them to concentrate on their work. Housing and studio access are provided free of charge. Artists, musicians, and writers working in a range of mediums may apply for residencies that last two weeks. There is a $35 application fee.
    Deadline: January 6, 2026.

    Rome Residency in Drawing, Painting, and Sculpture (U.K. and Commonwealth)
    The British School at Rome, in partnership with the Bridget Riley Art Foundation, invites applications from exceptional early- to mid-career artists who live in the U.K. or its Commonwealth countries and work in painting, drawing, or sculpture for a six-month residency from September 2026 to March 2027.
    Deadline: January 9, 2026.

    WORTHLESSSTUDIOS Photographer in Residence (International)
    The Photographer in Residence program is a one-month-long photography residency taking place inside an Airstream trailer converted into a darkroom. Analog photographers and photography-based artists have exclusive access to process film and make new work. Residents receive a $1,500 artist stipend; darkroom chemistry, film, and photo paper; the option to host a public program, and more.
    Deadline: 11:59 p.m. EST on January 20, 2026.

    If you’d like to list an opportunity, please contact [email protected].

    Do stories and artists like this matter to you? Become a Colossal Member today and support independent arts publishing for as little as $7 per month. The article December 2025 Opportunities: Open Calls, Residencies, and Grants for Artists appeared first on Colossal.


    Source: Colossal.

  • Learn CSS Flexbox for Beginners [Free 2-hour course]

    Learn CSS Flexbox for Beginners [Free 2-hour course]

    November 25, 2025
    Software

    Flexbox is a powerful CSS feature that lets you build user interfaces that fit any screen size. freeCodeCamp just published a Flexbox for beginners course where you’ll learn the concepts and code syntax by building your own website navigation bar.

    If you’ve ever struggled to center something with CSS or tried to make columns line up nicely, Flexbox simplifies this dramatically. With just a few properties, you can build modern layouts that “flex” to different screen sizes, without needing to write a bunch of custom media queries.

    Developer and teacher Indra (CodeWithIndra) will walk you through every Flexbox property step by step. You’ll learn how to align items along the main and cross axis, reorder elements without changing the HTML, control how items grow and shrink, and finally understand what flex-grow, flex-shrink, and flex-basis are really doing. He also shows real examples from sites like GitHub and DataDog, then demonstrates how to recreate pieces of their layout.

    The course ends with two small projects: centering an element vertically and horizontally (the thing everyone Googles at some point) and building a clean navigation bar using only Flexbox.

    If you want to improve your front end development skills, this course is a good way to invest a couple hours of your weekend. [2 hour YouTube course]:


    Source: freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More.

  • Design System Culture: What It Is And Why It Matters (Excerpt)

    Design System Culture: What It Is And Why It Matters (Excerpt)

    November 25, 2025
    Software

    This article is a sponsored by Maturing Design Systems

    Design systems have become an integral part of our everyday work, so much that the successful growth and maturation of a design system can make or break a product or project. Great tokens, components and organization aren’t enough — it is most often the culture and curation that creates a sustainable, widely-adopted system. It can be hard to determine where to invest our time and attention. How do we build and maintain design systems that support our teams, enhance our work, and grow along with us?

    Excerpt: Design System Culture

    Culture is a funny thing. We all have some intuition about how important it is—at least we know we want to work in a great culture and avoid the toxic ones. But culture is notoriously difficult to define, and changing it can feel more like magic than reality. One company culture can be inspiring for some and boring for others, a place of growth for some and stifling for others.

    Adding to the nuance, not only does your company have a culture as a whole, but it has many subcultures. That’s because culture is not created by any individual. Culture is something that happens when the same group of people gather together repeatedly over time. So, as a company grows, adding hierarchy and structure, the teams formed around specific goals, products, features, disciplines, and so on, all develop their own subcultures.

    You probably have a design subculture. You probably have a product ownership subculture. You probably even have a subculture forming around those folks who get on a Zoom call every Tuesday at lunch to knit and chat. There are hundreds or more subcultures at most good-sized organizations. It’s complicated, nuanced, and immensely important.

    When an individual is struggling with the way they are managed, one culture enables them to offer authentic feedback to their boss, while another leads them to look for a new job. When a company provides free lunch on Fridays, one culture creates a sense of gratitude for this benefit; another makes you feel like this free lunch comes with the expectation that you can’t ever leave work. One culture prioritizes financial results over respectful interactions. One culture encourages competition between teams, while another emphasizes collaboration with coworkers.

    Why Culture?

    At the beginning of 2021, my company was asked to help a large organization plan, design, and build a design system alongside the minimum viable product of a new product idea. This is the kind of work we truly love, so the team was excited to jump in.

    As an author of a book about design systems, I want nothing more than to tell you how amazingly this engagement went. Instead, it was a tremendous struggle. Despite this being the perfect kind of work for my team and I on paper, we had to make the hard decision to walk away from our client at the end of that year. Not because we couldn’t do the work. Not because of any technical challenges or budget concerns. The reason we gave was “cultural incompatibility.” In almost twenty years of running my own businesses, this had never happened to me. After all, our clients don’t come to us because they have everything figured out — they come because they know they need help. If we couldn’t guide them through a difficult season, why did we even exist!?

    Needless to say, it didn’t sit well with me. So, after following a few useless threads of fear that we just couldn’t cut it, I spent the next year diving down a rabbit hole of research on organizational culture. This next section is a summary of what I learned in that year and how I’ve been putting that to use since. To start, let’s find a common understanding of what culture is.

    What Is Culture?

    Over the last few decades, a lot has been said about workplace culture. From understanding why it matters and how it impacts the ways we lead, to offering methodologies for changing it. I’ve found tremendous value in the research and writings of Edgar Schein, a business theorist and psychologist. Schein offers a simple model to explain what culture is, breaking it down into three levels:

    Artifacts

    Artifacts are the top level of Schein’s model. These are the things people think of when you say “culture” — the visible perks a company offers. I once worked at a place where we could expense bringing in donuts for the team. Another job I had provided a foosball table. One company encouraged us to cook lunch together each week. These kinds of things, along with the company swag, the channel in Slack where you get to brag about your peers, and the company retreat are all “artifacts” of your company culture.

    Espoused Values And Beliefs

    The next layer down is called “espoused values and beliefs.” This is what people inside the culture say they believe. It’s the list of values, the mission statement, the vision. It’s the content on the website and plastered on the walls. It’s the stuff you expect to get when you accept the job because it’s how people answered all your questions throughout the interview process.

    Basic Underlying Assumptions

    The deepest layer is called “basic underlying assumptions.” This is what people inside the organization actually believe. It’s the way the leadership and employees behave, most notably

    in the face of a difficult decision. This layer is the root of your culture. And no matter what you show (artifacts), no matter what you say (espoused beliefs), the things you believe (underlying assumptions) will come out eventually.

    It Starts At The Bottom

    As an employee, you will experience these things from the top down. On your first day, you observe what’s happening around you — you see the artifacts of the culture. Eventually, you get to know a few folks. As you have more and more conversations with them, you’ll begin to hear how they talk about the culture — their espoused beliefs. At some point, people inside your culture will be faced with some tough situations. This is where the rubber meets the road and when you’ll learn what those individuals’ basic underlying assumptions are.

    Unhealthy organizations don’t have a process for surfacing and valuing those underlying assumptions. Healthy organizations know that culture starts with the basic underlying assumptions of every individual at the company.

    Unhealthy organizations try to create culture with perks and mission statements. Healthy organizations allow the top two layers to emerge naturally from the bottom layer.

    When the basic underlying assumptions don’t line up with the espoused beliefs and artifacts, the disconnect is strong. It’s often hard to articulate the problem, but people will feel it. This is the company with a core value of “family first” that requires you to travel all the time with no recognition of the impact it has on your actual family. The espoused belief to prioritize family is not actively supported in the decisions being made.

    Strength And Weakness

    We all subconsciously know these things, and that is reflected in the language we use as we talk about the culture of an organization. We tend to use the words “strong” and “weak” to describe culture. You might say, “That company has a strong culture.” This statement is an indication that the layers are aligned, and that means the culture itself serves as a way of guiding decisions. If we all have shared values, we can trust one another’s ability to make decisions that will align with those values.

    Conversely, an organization with a weak culture is missing the alignment between the things they say and the decisions they make. These cultures often continually add policies and procedures in order to police the behavior of individuals. In this scenario, the culture is weak because it doesn’t offer the organic guidance a stronger culture does — the misalignment means the things we choose to do differ from the things we say.

    That is not to say policies and procedures are bad. As companies grow, there is a need to document the expectations for people. The proactive nature of a strong culture means these documents are often a formalization of what has emerged organically, whereas a weak culture reacts to negative situations in hopes to prevent the bad from happening again.

    Editor’s Note

    Do you like what you’ve read so far? This is just an excerpt of Ben’s upcoming book, Maturing Design Systems, in which he explores the anatomy of a design system, explains how culture shapes outcomes, and shares practical guidance for the challenges at each stage — from building v1 and growing healthy adoption to navigating “the teenage years” and ultimately running a stable, influential system.

    Table of Contents

    • Context
      An introduction to the context of design systems, understanding where they live in your organization, what feeds them, and whether you should build one.
    • Design System Culture
      A deep dive into what culture is, why it’s important for design system teams to understand, and how it unlocks the ability for you to deliver real value.
    • The Anatomy of a Design System
      An exploration of the layers and parts that make up a design system based on the evaluation of hundreds of design systems over many years.
    • Maturity
      An over view of the design system maturity model including the fours stages of maturity, origin stories, a framework for maturing in a healthy way, and a framework for creating design system stability.
    • Stage 1, Building Version One
      A dive into what it means to be in stage 1 of the design system maturity and a few mental models to keep you focused on the right things in this early stage.
    • Stage 2, Growing Adoption
      Unpacking stage 2 of the design system maturity model and a deep dive into adoption: broadening your perspective on adoption, the adoption curve, and how to create sustainable adoption.
    • Stage 3, Surviving the Teenage Years
      Understanding the relevant concerns for stage 3 of the design system maturity model and how to address the more nuanced challenges that come with this level of maturity.
    • Stage 4, Evolving a Healthy Program
      Exploring what it means to be in stage 4 of the design system maturity model, when you’ve become an influential leader in the eyes of the rest of your organization.

    About The Author

    Ben Callahan is an author, design system researcher, coach, and speaker. He founded Redwoods, a design system community, and The Question, a weekly forum for collaborative learning. As a founding partner at Sparkbox, he helps organizations embed human-centered culture into their design systems. His work bridges people and systems, emphasizing sustainable growth, team alignment, and meaningful impact in technology. He believes every interaction is an opportunity to learn.

    Reviewers’ Testimonials

    “This book is a clear and insightful blueprint for maturing design systems at scale. For well-supported teams, it offers strategy and clarity grounded in real examples. For smaller teams like mine, it serves as a North Star that helps you advocate for the work and find solutions that fit your team’s maturity. I highly recommend it to anyone building a design system.”

    — Lenora Porter, Product Designer

    “Ben draws connections between process, collaboration, and identity in ways that feel both intuitive and revelatory. Many design system books live comfortably in the tactical and technical, but this one moves beyond the how and into the why — inviting readers to reflect on their roles not just as product owners, designers or engineers, but as stewards of shared understanding within complex organisations. This book doesn’t prescribe rigid solutions. Instead, it encourages self-inquiry and alignment, asking readers to consider how they can bring intentionality, empathy, and resilience into the systems they touch.”

    — Tarunya Varma, Product Design Manager, Tide

    “Ben Callahan’s Maturing Design Systems puts language to the struggles many of us feel but can’t quite explain. It unpacks the hidden influence of culture, setup, and leadership, providing you with the clarity, tools, and frameworks to course-correct and move your system work forward, whether you’re navigating a growing startup or a scaling enterprise.”

    — Ness Grixti, Design Lead, Wise, and Author of “A Practical Guide to Design System Components”

    Don’t Miss Out!

    Through years of interviews, coaching, and consulting, Ben has discovered a model for how design systems mature. Understanding how systems tend to mature allows you to create a sustainable program around your design system — one that acknowledges the human and change-management side of this work, not just the technical and creative.

    This book will be a valuable resource for anyone working with design systems!

    Spread The Word

    Sign up to our Smashing newsletter and be one of the first to know when Maturing Design Systems is available for preorder. We can’t wait to share this book with you!


    Source: Articles on Smashing Magazine — For Web Designers And Developers.

  • 50 Cent’s Diddy Docuseries Gets Title and Netflix Release Date

    50 Cent’s Diddy Docuseries Gets Title and Netflix Release Date

    November 25, 2025
    Music

    Sean Combs: The Reckoning, a Netflix docuseries about Sean “Diddy” Combs’ rise and fall from grace, will arrive on Tuesday, December 2. Long in the works, the series of four hourlong episodes is executive-produced by 50 Cent and directed by Alexandria Stapleton.

    The series will feature new interviews with “those formerly in his orbit,” according to a Netflix press release, but no further details were given. In an interview about the series, 50 Cent said, “I’m grateful to everyone who came forward and trusted us with their stories, and proud to have Alexandria Stapleton as the director on the project to bring this important story to the screen.”

    Stapleton added, “This isn’t just about the story of Sean Combs or the story of Cassie, or the story of any of the victims, or the allegations against him, or the trial. Ultimately, this story is a mirror [reflecting us] as the public, and what we are saying when we put our celebrities on such a high pedestal. I hope [this documentary] is a wake-up call for how we idolize people, and to understand that everybody is a human being.”

    Diddy is currently serving a prison sentence of more than four years for two counts of transportation to engage in prostitution. He is also facing numerous civil lawsuits and, as of this month, an investigation by the Los Angeles County sheriff’s department into new allegations of sexual battery.


    Source: RSS: News.

Previous Page
1 … 49 50 51 52 53 … 911
Next Page
MONIMEGA
  • Instagram
  • Facebook
  • Twitter
Gestisci Consenso
Per fornire le migliori esperienze, utilizziamo tecnologie come i cookie per memorizzare e/o accedere alle informazioni del dispositivo. Il consenso a queste tecnologie ci permetterà di elaborare dati come il comportamento di navigazione o ID unici su questo sito. Non acconsentire o ritirare il consenso può influire negativamente su alcune caratteristiche e funzioni.
Funzionale Always active
L'archiviazione tecnica o l'accesso sono strettamente necessari al fine legittimo di consentire l'uso di un servizio specifico esplicitamente richiesto dall'abbonato o dall'utente, o al solo scopo di effettuare la trasmissione di una comunicazione su una rete di comunicazione elettronica.
Preferenze
L'archiviazione tecnica o l'accesso sono necessari per lo scopo legittimo di memorizzare le preferenze che non sono richieste dall'abbonato o dall'utente.
Statistiche
L'archiviazione tecnica o l'accesso che viene utilizzato esclusivamente per scopi statistici. L'archiviazione tecnica o l'accesso che viene utilizzato esclusivamente per scopi statistici anonimi. Senza un mandato di comparizione, una conformità volontaria da parte del vostro Fornitore di Servizi Internet, o ulteriori registrazioni da parte di terzi, le informazioni memorizzate o recuperate per questo scopo da sole non possono di solito essere utilizzate per l'identificazione.
Marketing
L'archiviazione tecnica o l'accesso sono necessari per creare profili di utenti per inviare pubblicità, o per tracciare l'utente su un sito web o su diversi siti web per scopi di marketing simili.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Visualizza le preferenze
  • {title}
  • {title}
  • {title}