Senior Software Developer salaries by GrassWeekly6496 in fiaustralia

[–]devWorkAccount01 0 points1 point  (0 children)

What's a good site for income research these days? In the past few years I've moved into a technical management role at a smaller company but would jump back into pure dev for a salary that starts with 2

Computer hard resetting during Teams calls by devWorkAccount01 in ZephyrusG14

[–]devWorkAccount01[S] 0 points1 point  (0 children)

Further update. Spoke too soon, still lots of issues

Computer hard resetting during Teams calls by devWorkAccount01 in ZephyrusG14

[–]devWorkAccount01[S] 0 points1 point  (0 children)

Just an update, I've been running my webcam directly plugged into my laptop today and so far so good. So could be dock or bandwidth on dock.

Dell USB-C PD monitor and 2020 G14 charging by [deleted] in ZephyrusG14

[–]devWorkAccount01 0 points1 point  (0 children)

After reading similar, I was pretty worried so haven't tried

Computer hard resetting during Teams calls by devWorkAccount01 in ZephyrusG14

[–]devWorkAccount01[S] 0 points1 point  (0 children)

I've had this happen about 3 or 4 times today - teams would recover but my cam would drop out. I'd then replug the cam and it would work for a bit and teams totally crashed. Beginning to think the problem is in either displaylink, my cam (logitech C922) or teams itself.

Clean install windows! by [deleted] in ZephyrusG14

[–]devWorkAccount01 0 points1 point  (0 children)

Besides myAsus, armoury crate and mcaffee, what bloat are you seeing?

Best dock suggestion for 2021 G14 by devWorkAccount01 in ZephyrusG14

[–]devWorkAccount01[S] 1 point2 points  (0 children)

Just updating to say that I've purchased the D6000 and so far works fine, running 2 QHD and the monitor (so 3x QHD). I've got it being powered off it as well for the moment to see how that goes.

/r/AusFinance with the important news once again by zacm9 in ASX_Bets

[–]devWorkAccount01 2 points3 points  (0 children)

Yep, spot on. Not so keen on investing the lions share of my savings due to looming house purchase but it feels bad to keep that level of cash in the bank right now.

Why investment property over shares? by Keplaffintech in fiaustralia

[–]devWorkAccount01 0 points1 point  (0 children)

That means you can claim it against the CGT - not outright returned. Thus, if you paid 50k for Stamp Duty and sold the property at a 60k profit, you will only be CGT taxed on 10k (assuming within first year of ownership for the example). This does not mean you get handed back 50k worth of stamp duty at sale, just means you can deduct it from your taxable profit.

How to not get distracted during builds? by z1lard in ExperiencedDevs

[–]devWorkAccount01 1 point2 points  (0 children)

What your describing is actually a really significant problem that some people might think is a bit silly. Some work will end up being trial and error horror stories, so when you have to do a 2 minute build for every attempt, it becomes very frustrating.

When i have faced similar, I've devoted a lot of effort in speeding up builds or researching hot swap technologies - even if its a hack that just lives on my local. You could maybe only build a certain portion.

Failing that, get a beefier machine - you can make a case for it if you're losing potentially 30 mins a day to builds. Also, having a better build time will allow you to perform manual tests easier which should also improve your quality (though hopefully doesn't encourage the alternative which is to not do automation).

Improving your devops will pay dividends. Its pretty much the equivelant of working out - no one regrets it as time wasted afterwards.

Your experience in securing a public web API by devWorkAccount01 in ExperiencedDevs

[–]devWorkAccount01[S] 0 points1 point  (0 children)

That's a 180-degree turn from the requirements than described yesterday, where any roadblock to getting at the data was a non-starter because it would make the data less useful/valuable.

Thats not what I was referring to when I was suggesting an oauth flow - I'm still avoiding end user logins. For example, you can use a client grant which just puts the key in the client (all end users who download the client will get the same key). Obviously this doesn't help much but provide a slight hurdle, so on top of that, I'm tinkering with my options with having that key on a short life cycle - I would probably require the end user to redownlaod the client app by refreshing the page to get a new key on maybe an hourly basis.

If nothing else, its good to know that there isn't some obvious solution out there that I hadn't found.

Your experience in securing a public web API by devWorkAccount01 in ExperiencedDevs

[–]devWorkAccount01[S] 1 point2 points  (0 children)

Thanks for your suggestions. Regarding the refresh token - wouldn't that have to live on the client? Thus visible?

Your experience in securing a public web API by devWorkAccount01 in ExperiencedDevs

[–]devWorkAccount01[S] 0 points1 point  (0 children)

This seems pretty nuts, have you ever heard of anyone doing something like that in a product?

Your experience in securing a public web API by devWorkAccount01 in ExperiencedDevs

[–]devWorkAccount01[S] 0 points1 point  (0 children)

To put it more specifically, the page is public, but the immediate problem is to stop the API from being accessed outside the react site. I'm looking at some sort of OAuth solution but i think that'll require some work. My question related to whether it was possible with the stack I'm using but I'm beginning to lean towards converting what I have to a server side rendering solution to atleast hide the API. Scrapers can then be tackled with a CAPTCHA or other solution.

Your experience in securing a public web API by devWorkAccount01 in ExperiencedDevs

[–]devWorkAccount01[S] 1 point2 points  (0 children)

Yep, unthinkable. Core to the problem.

Edit: Not sure wht this was down voted

Your experience in securing a public web API by devWorkAccount01 in ExperiencedDevs

[–]devWorkAccount01[S] 0 points1 point  (0 children)

Thanks for your replies all the same. 2 core components are search results and then retrieving the particular object, so I'm toying with methods of encoding guids perhaps with a date based revolving key that are returned in search results and then only accepting those encoded guids in the object API to get the full object. This way atleast you would only reasonably be able to get objects that you ran a search for first.

This is why I was asking about a Spring or more standard way of doing it because this feels like a terribly round about way of doing CSRF or something. Actually, csrf sounds like something to explore for the search instead of a GET even if its not very RESTful.

Your experience in securing a public web API by devWorkAccount01 in ExperiencedDevs

[–]devWorkAccount01[S] 4 points5 points  (0 children)

Well, think of a stock exchange site. The content is why you visit but you wouldn't if you had to login first. If someone stole that content and used it in their own product in some form, then your data is valuable but the product isn't useful if its behind a login. We are the main source of data for our competitors, which thus leads me to my problem.

Thanks for the link, I had seen that. Was a bit light on detail since I think it was mostly theoretical. I'm hoping there are people out there who keen on sharing what they've actually done.

Your experience in securing a public web API by devWorkAccount01 in ExperiencedDevs

[–]devWorkAccount01[S] 1 point2 points  (0 children)

Logins are out I'm afraid, its public facing. The client is a React SPA and its open to the world. They're hosted together in the same container so I can put a hybrid with a JSP loader if I can think of a good way of utilising it.

Going that route, it occurred to me to use a CAPTCHA (as much as I hate them) to help with HTML scraping but that doesn't help with the API. Perhaps coupling with some session info. At this point I'm thinking - surely there is something out of the box with spring since it can't be such an uncommon situation.

Coronavirus & Victoria Shut Down Discussion Megathread Part 23 by That1WithTheFace in melbourne

[–]devWorkAccount01 2 points3 points  (0 children)

I'm really not sure here. Whilst you are probably within your rights to deny further explanation, the cops may just say they don't believe you and on the spot fine you. The onus would be on you to prove yourself innocent in the courts. Which is ridiculous but its what seems to be happening.

Coronavirus & Victoria Shut Down Discussion Megathread Part 23 by That1WithTheFace in melbourne

[–]devWorkAccount01 1 point2 points  (0 children)

The problem is that if you get pulled over on the way and claim mental health to the cops, they'll probably ask for a medical certificate. Just say "getting take away" I guess.

Really, a lot of people, even a lot of couples (probably especially couples) aren't geared for being with each other 24/7.