SShortSingh.
Back to feed

Developer builds browser-only receipt scanner that keeps all data on your device

0
·1 views

A developer built a receipt scanning tool that runs entirely in the browser using Tesseract.js, ensuring no images or data are ever uploaded to a server. The motivation was privacy: receipts can reveal sensitive details like medical providers, locations, and partial card numbers. The tool works offline after the first visit, though initial load is slow on mobile due to the WASM build and language model download. Faded thermal receipts are flagged rather than guessed, since silent errors in tax-related data are worse than acknowledged failures. Most of the engineering effort went into parsing raw OCR text into structured fields like date, vendor, and total — a messy problem solved through heuristics tested on real receipts.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

How One Developer Cut 15 Tool Pages to Under 2-Second Load Times

A frontend developer optimized a React-based utility platform called TinyUtils, bringing first contentful paint down to 1.2 seconds and time to interactive to 1.8 seconds on 4G. The key changes included code-splitting with React.lazy, which reduced the initial bundle from roughly 800KB to 220KB. Non-critical page content was deferred using Intersection Observer, while images were converted to WebP and AVIF formats, cutting average image sizes by around 60%. Dependency auditing replaced heavy libraries like moment.js and lodash with lighter alternatives, trimming another 150KB from the bundle. Combined with Vite build optimizations and Brotli compression, the site's Lighthouse performance score improved from the 50s to the 90s.

0
ProgrammingDEV Community ·

How to Convert iPhone HEVC Videos for Telegram Video Avatars Using FFmpeg

Telegram video avatars silently reject uploads that do not meet strict technical requirements, including H.264 codec, yuv420p colorspace, 800x800 resolution, no audio, and a file size under 2 MB. iPhones have recorded video in HEVC (H.265) by default since iOS 11, making them incompatible with Telegram's video avatar endpoint without conversion. A developer discovered these undocumented constraints while building a Telegram bot, after users repeatedly reported that their iPhone videos were not being set as profile avatars. The fix involves using FFmpeg to transcode the video, applying crop detection to remove letterboxing, and setting the faststart flag so Telegram's server can read the file metadata sequentially. A sample Python bot implementation using aiogram and asyncio demonstrates how the conversion pipeline can be automated for end users.

0
ProgrammingDEV Community ·

CTF Write-Up: SQL Injection via Base64 Parameter Cracks Intigriti's Critter Gallery

Security researcher solved Intigriti's Challenge 0926, a capture-the-flag puzzle disguised as an animal photo gallery, on September 27, 2026. The vulnerability stemmed from a base64-encoded query parameter that passed user input directly into a single-quoted SQL string without sanitization. A behavioral mismatch between PHP's case-sensitive image lookup and MySQL's case-insensitive description query revealed that two separate layers processed the same input differently, signaling a potential injection point. Using classic SQL injection techniques — including a boolean-based proof and a UNION-based extraction — the researcher enumerated the database schema and dumped a hidden table called secret_vault. The flag, INTIGRITI{01a09f56-74a2-700b-a849-ffe6742327b2}, was retrieved in 14 probing steps and accepted by Intigriti.

0
ProgrammingDEV Community ·

How a Single Buggy Audit Tool Took Down Meta's Entire Network for Six Hours

On 4 October 2021, Facebook, Instagram, and WhatsApp became unreachable worldwide for roughly six hours after a routine backbone maintenance command severed all connections between Meta's data centres. A built-in audit tool designed to prevent such a command from executing had an undetected bug, allowing the instruction to run unchecked. Because Meta's edge DNS servers are designed to withdraw their BGP routes when they lose contact with data centres, every server did so simultaneously, making Meta's services invisible to the internet. Recovery was severely delayed because remote access tools and internal diagnostics both depended on the very network and DNS infrastructure that had gone down, forcing engineers to travel physically to data centres. The outage was ultimately caused by a circular dependency in Meta's recovery architecture and an automated safety mechanism that lacked a fail-safe against a total simultaneous failure across all locations.