SShortSingh.
Back to feed

Developer builds Elixir Pix payment library, validates it with a real one-cent transaction

0
·1 views

A developer built pix_brcode, an open-source Elixir library for generating and parsing Brazil's Pix instant payment QR codes, after finding no maintained equivalent on Hex, Elixir's package manager. Pix, launched by Brazil's Central Bank in 2020, is a free, real-time payment system widely used across the country, with codes based on the EMVCo TLV (Tag-Length-Value) format plus a CRC16 checksum. The library was built over a weekend and deliberately avoids external dependencies, including a hand-written CRC16 implementation to keep the package self-contained. To handle money accurately, the library accepts amounts as integer cents or exact strings rather than floating-point numbers, avoiding classic precision errors. The developer verified the library works in production by successfully completing a real R$0.01 Pix transaction, uncovering and fixing a bug that only surfaced when an actual bank was involved.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

Migrating from Modern Events Calendar: Key Database Quirks Developers Must Know

Modern Events Calendar Lite was permanently removed from WordPress.org on May 11, 2022, for a guideline violation, though many sites continue running it via the developer's own distribution. Each event is stored as a custom post type called 'mec-events', with scheduling data held in post meta fields rather than the plugin's derived database tables. Developers migrating away from the plugin face several data pitfalls, including weekly repeat intervals stored in days instead of weeks, occurrence counts saved as one less than the user-entered value, and ISO-formatted weekday numbers that differ from PHP and JavaScript conventions. Advanced monthly repeat rules are stored as compact tokens such as 'Sun.1' or 'Fri.l', while location or organizer ID 1 is a placeholder meaning 'hide it' and should not be imported as a real venue. Auditing raw post meta with direct database queries is recommended before attempting any migration to avoid silently incorrect dates or repeat schedules.

0
ProgrammingDEV Community ·

SentinelMind AI Agent Uses Persistent Memory to Cut Security Incident Resolution Time

A team built SentinelMind, an AI-powered incident response agent, as part of the HackwithHyderabad 3.0 hackathon. Unlike conventional security tools, SentinelMind uses a persistent memory layer called Hindsight to store details of every past incident, including the fix applied and time taken to resolve it. When a new alert arrives, the agent first searches its memory for similar past incidents and surfaces relevant solutions rather than starting from scratch. The team's Memory Impact dashboard showed resolution times dropping from over 40 minutes for early incidents to under 15 minutes once sufficient memory had accumulated. A key architectural decision was to have the LLM only explain figures derived from stored records, preventing the model from fabricating statistics and making the system more reliable.

0
ProgrammingDEV Community ·

Azure Resources Wiped in 7 Minutes as Storm-3168 Exploits Compromised Service Principals

Microsoft Security Research documented a critical cloud attack by threat group Storm-3168, in which two compromised Azure service principals carried out coordinated reconnaissance and destruction within a single victim tenant. One service principal conducted over 300 read operations across roughly 15.5 hours, while a second rapidly enumerated virtual machines and resource groups in approximately five seconds. About 16 hours after initial reconnaissance, the second principal deleted multiple storage accounts, a Key Vault, a Function App, and an App Service plan in a destructive sequence lasting around seven minutes. Approximately 30 minutes after the deletions, the attacker re-enumerated storage accounts and successfully issued over 30 ListKeys requests to harvest access credentials. Attempts to disable Site Recovery and backup protection locks were also observed, though those specific actions failed.

0
ProgrammingDEV Community ·

How to Strip GPS EXIF Data Before Publishing Images in Node.js Express Apps

A developer guide outlines a secure image publishing pipeline for Node.js Express applications that strips GPS and EXIF metadata before any upload becomes publicly accessible. The approach uses Sharp for re-encoding uploads as fresh JPEG or WebP files, ensuring metadata is not carried over from the original. After re-encoding, the output bytes are parsed and verified using the exifr library, and the publish job is rejected if any GPS location fields are still detected. The original upload is kept access-controlled as evidence, while only the verified, metadata-free derivative is stored and published. The method also enforces an 8 MB request size limit and includes unit tests covering phone photos with GPS tags, orientation-tagged screenshots, and images with no EXIF data.