SShortSingh.
Back to feed

Same JSON, Six Parsers, 19 Divergent Outcomes: A Developer's Stress Test

0
·3 views

A developer fed 24 deliberately tricky JSON documents to six popular parsers — Python, Node.js, Ruby, Perl, jq, and Swift — and found that only five of the 24 documents produced identical results across all six. Key divergences included duplicate object keys, where five parsers kept the last value while Swift kept the first, creating a potential security gap in systems where two services read the same payload differently. Node.js silently truncated large integers beyond 2^53 due to IEEE 754 floating-point limits, with no error or warning, a common source of database ID corruption. Several documents were accepted by some parsers and rejected by others, including lone Unicode surrogates, trailing commas, and numbers like NaN or Infinity, which are not valid JSON. The findings highlight that RFC 8259 leaves enough ambiguity for individually correct parsers to behave in ways that break cross-service pipelines in practice.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

Developer builds open-source fuzzy search library inside PostgreSQL without schema changes

A software developer built an open-source PHP library called Fuzzphony to enable forgiving, typo-tolerant search within an existing PostgreSQL database after being unable to modify the schema or add new infrastructure like Elasticsearch. The library leverages built-in PostgreSQL features — full-text search via tsvector and tsquery, the unaccent extension, and pg_trgm trigram similarity — to handle typos, accent variations, and word stemming. Fuzzphony maintains its own shadow index tables alongside the original data, avoiding any changes to production schemas. The library supports ranked results, field weighting, filter columns, query exclusions, and user-input sanitisation, with warnings returned for malformed queries. Currently at version 0.4 and under active development, Fuzzphony is open source with a stable core but an API that may change before the 1.0 release.

0
ProgrammingDEV Community ·

Developer Builds AI Incident Response Tool That Learns from Past Outages

A developer created MemoryOps, an AI-powered incident response platform for DevOps and SRE teams, designed to eliminate hallucinated citations during live outages. The tool combines a React frontend, FastAPI backend, and SQLite database with a persistent memory layer called Hindsight and the Groq Cloud LLM for reasoning. When an incident is resolved, structured learnings are stored in Hindsight and later retrieved to ground AI recommendations in verified past experience rather than invented references. The system is deliberately human-supervised, meaning no actions are taken autonomously and engineers remain in full control throughout the workflow. The architecture separates real-time incident data from historical learnings, with SQLite tracking current incidents and Hindsight supplying context from previously resolved ones.

0
ProgrammingDEV Community ·

Adobe Commerce Adds MCP Server to Expose Store Data as AI Agent Tools

Adobe announced a Commerce MCP server at its Summit 2026 event in April, designed to give AI agents like ChatGPT and Gemini real-time access to catalog, cart, pricing, inventory, and checkout data. The move reframes a store's catalog from data rendered by a frontend into a named, schema-defined function that external language models can call autonomously. The feature is currently listed as "coming soon" on Adobe's official pages, though some Adobe partners report it is already running on client projects. It is primarily tied to Adobe Commerce as a Cloud Service, meaning merchants on PaaS or on-premise Magento installations should not expect automatic access. Key technical details such as exact tool names, schemas, authentication models, and rate limits have not yet been publicly disclosed by Adobe.

0
ProgrammingDEV Community ·

Developer Builds Security Hook That Forces Claude Code to Fix Vulnerabilities Before Finishing

A developer discovered that Claude Code, after being asked to add an AI chat feature, produced working code that also contained hardcoded API keys, unsafe innerHTML rendering, and eval() calls before declaring the task complete. To address this, the developer built a verification loop using Claude Code's Stop hook, which intercepts Claude's completion signal and scans only the changed lines of code for five common AI-generated security mistakes. If any issues are found, the hook returns an exit code 2 along with a detailed report, forcing Claude to revise the code before it can finish. After a maximum of three failed attempts, the hook stops blocking and instead writes a security report for a human reviewer, preventing infinite loops. The project is shared as a drop-in configuration folder containing the hook, settings, and a skill file that instructs Claude on how to properly remediate each flagged issue.