SShortSingh.
Back to feed

Dev builds abuse-resistant referral system by rewarding listings, not signups

0
·2 views

A developer building Adsyte, a free directory for indie projects, has shared the fraud-resistant referral system they recently shipped for the platform. Instead of awarding tokens when a referred user signs up, the system only pays out when the recruit publishes their first listing, making abuse significantly harder. Additional safeguards include duplicate-URL detection, hCaptcha verification, a Redis-based mechanism to prevent double payouts, and a daily reward cap per referrer. Referral codes are generated as HMACs of user IDs rather than stored as random tokens, reducing the risk of leaks or unnecessary data overhead. The developer describes the core principle as 'pay for the outcome, not the action,' arguing this approach eliminates the need for bolt-on fraud detection altogether.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingHacker News ·

Anthropic's Claude AI Hit by Authentication Outage, Status Page Silent

Claude, the AI assistant developed by Anthropic, experienced a service disruption that prevented users from logging in. The platform returned an 'Authentication service was unavailable' error message during the outage. Anthropic's official status page showed no acknowledgment of the issue at the time. However, user-reported outage tracking site Downdetector reflected a spike in complaints, confirming the disruption was widespread.

0
ProgrammingDEV Community ·

A developer built a tool to let freelancers report bad clients without exposure

Freelancer Arun is owed ₹1,20,000 by a design agency since January, but fears publicly naming the client will cost him future work — a dilemma shared silently by three others in the same Discord server. A developer built an agent over a hackathon weekend to let multiple claimants coordinate against a defaulting client without ever revealing their identities to each other or the accused. The tool posts anonymised matter cards on Discord showing only a vague amount band, a time range, and a headcount — never the agency's name. Victims identify the relevant matter by guessing the client and then proving it by naming them independently via email, serving as a self-selecting admission test. The system is deliberately designed so no stored data links a Discord identity to a claimant, eliminating the central leak risk that undermines most whistleblower-style platforms.

0
ProgrammingDEV Community ·

Developer Builds Layered X Post Automation Using OpenAI Codex and xurl CLI

A developer has published a detailed guide on building a scheduled X (formerly Twitter) publishing workflow using OpenAI's Codex and xurl, the official X API command-line client. The system is structured into four layers: an X developer app with read-write authentication, xurl for credential storage and API communication, a Codex skill that verifies account identity before every post, and a scheduled Codex task that researches, drafts, and publishes content. The architecture deliberately separates editorial decision-making from the publishing command, preventing the AI from freely choosing accounts or improvising posts. The guide emphasizes that a well-defined editorial policy — specifying what the automation may and may not publish — is as critical as the technical setup. The workflow was verified in August 2026, and readers are advised to consult current upstream documentation before deploying it in production.