When you forget to rate limit the 'like' endpoint
Description
This is a close-up screenshot of a user interface, likely a social media or content platform, with a dark mode theme. It features two prominent buttons for user reactions: a cyan 'thumbs up' icon with a massive count of 167,033, and a magenta 'thumbs down' icon with a much smaller count of 1,190. Below these buttons, a fragment of code is partially visible. The caption provided for this image was: "Finally someone made a bold move and start to abuse that like button. Still waiting for someone to run a few bots clicking those meaningless buttons 24/7 :D". The technical humor comes from the implication that the absurdly high 'like' count is not organic but the result of a script or bot repeatedly hitting an API endpoint. This scenario is relatable to senior developers who have to design systems resilient to such abuse, often by implementing measures like rate limiting or CAPTCHAs. It serves as a commentary on the vanity of engagement metrics and the ease with which they can be manipulated
Comments
23Comment deleted
The frontend shows 167k likes, but the backend logs show one IP address, a cron job, and a comment saying '// TODO: Add rate limiting before this goes viral'
167 033 up, 1 190 down - turns out leaving “bypassRateLimit=true” enabled in prod is the quickest A/B test for your bot detector
After 167,033 iterations, even the loop itself started upvoting the break statement out of sheer exhaustion - proving that sometimes the real O(n) complexity is the emotional damage we accumulate along the way
When your Stack Overflow question about semicolons gets 167k upvotes, you know you've either solved the P=NP problem or asked 'Why does my JavaScript work without semicolons?' The ratio suggests this developer discovered the ancient secret: the community's collective trauma over missing semicolons transcends all programming languages, frameworks, and even that one time someone suggested Python's whitespace sensitivity was 'intuitive.'
That 167,033 upvotes is what happens when a non-idempotent Like API meets an auto-retrying client and React StrictMode double-invokes your onClick
167,033 👍, 1,190 👎 - PM calls it “validated.” The diff is one line: break; We didn’t fix the feature, we shipped a circuit breaker for our vanity metrics
167k upvotes prove 'v; break;' scales better than any microservices refactor
I'm too lazy to do that thing Comment deleted
принято Comment deleted
Please, refrain from usage of any language besides English in dev meme 🙏 Comment deleted
No problem Comment deleted
это где Comment deleted
Please, refrain from usage of any language besides English in dev meme 🙏 Comment deleted
Just dropped by devme.me & added another 100+ likes.😌😂 Comment deleted
Nice! Comment deleted
look at the counter now Comment deleted
I will say; people up to this point have had zero talent for spamming APIs. why do I have to be the bringer of chaos? Comment deleted
got 1M likes now 🔥 Comment deleted
ok but … that doesn't persist Comment deleted
Who said that it’s gonna be plain easy tho? 🌚 Comment deleted
Where is that? Comment deleted
I'm also curious where's that going on. Tag me too, please 🫶 Comment deleted
@Diotost @SoutHora what do you mean? It’s on main page of devme.me Comment deleted