SShortSingh.
Back to feed

How to Design a Secure SMS OTP and Airline Alert Backend with Rate Limiting

0
·1 views

A software architecture guide outlines best practices for building SMS OTP login systems, email receipts, and airline disruption alerts with proper rate limiting and idempotency controls. For OTP security, it recommends storing hashed codes with expiry timers, capping verification attempts, and separating user cooldowns from transport-level retries, in line with NIST SP 800-63B guidelines. Payment receipts should be tied to versioned events using a business idempotency key, ensuring that replaying an event does not generate duplicate messages. Airline alert notifications should run on a separate queue to prevent schedule-change bursts from blocking login flows. The guide also warns against storing email templates in delivery dashboards, favoring repository-owned templates that keep wording, escaping, and migration logic under a single reviewable boundary.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

Solid-Vue JS Brings File-Based API Routing to Vue and Vite Projects

A developer has released Solid-Vue JS, a meta-framework built on Vue, Vite, and the h3 server library, designed to eliminate repetitive backend setup for small Vue projects. The framework was inspired by frustrations encountered while building a mini ERP application, including version conflicts, manual routing configuration, and the overhead of larger frameworks like Nuxt. Its core feature is file-based API routing, where placing a file in the server/api directory automatically creates an API endpoint, keeping frontend and backend code within a single project. Solid-Vue JS ships as three npm packages covering the core framework, project scaffolding, and a CLI for adding integrations such as Tailwind CSS and icon libraries. Currently in beta, the framework supports one-command deployment to Cloudflare Workers and its packages are available on npm, with documentation live at docs.solid-vue.tech.

0
ProgrammingDEV Community ·

Developer Builds AI Support Agent With Persistent Memory Across Conversations

A developer has created a customer support AI agent that retains context from past interactions, addressing a key limitation of conventional stateless support bots. Most LLM-based support agents handle only the current conversation, forcing customers to repeat information each time they return. The new system uses a tool called Hindsight to store structured memories — including reported issues, troubleshooting steps, preferences, and prior commitments — linked to individual customers. Hindsight offers three core operations: retaining information from conversations, recalling relevant past context, and synthesizing responses based on memory. The approach aims to make support interactions more coherent and cost-efficient by retrieving only relevant history rather than passing entire conversation logs back to the model.

0
ProgrammingDEV Community ·

Developer Builds AI Agent TRACE to Track Product Problem History Over Time

A developer has built an AI agent called TRACE — short for Tracking Reactions, Actions, Consequences & Evolution — designed to help product teams remember the full history of customer problems. Unlike standard AI tools that treat each piece of feedback in isolation, TRACE treats recurring issues as persistent entities with a lifecycle. The system maps a problem from initial customer feedback through product decisions, interventions, and outcomes, storing that history for future reference. This allows teams to quickly determine whether a current issue has appeared before and what was previously attempted to resolve it. The project is publicly available on GitHub, with a live demo hosted on Vercel.

0
ProgrammingDEV Community ·

Developer Builds Python-Based IEC 61850 GOOSE Substation Protection Simulator

A power engineering graduate has built an end-to-end Python pipeline simulating IEC 61850's GOOSE protocol, which allows substation protection devices to communicate over a network instead of traditional hardwired connections. The project comprises three components: a publisher-subscriber relay-breaker pair exchanging GOOSE trip messages, fault simulation logic using pandapower that automatically triggers trip signals when fault current exceeds a threshold, and a live Streamlit monitoring dashboard displaying relay status, event logs, and fault graphs. GOOSE messaging in real IEC 61850 networks operates in under 4 milliseconds, making it suited for time-critical protection events. The developer noted that simulating fault currents before triggering protection logic provided practical insight into relay coordination that textbooks alone cannot convey. As power grids increasingly integrate renewables and automation, IEC 61850-based protection systems are becoming industry standard, making hands-on experience with the protocol increasingly valuable.