The Notification Echo — Python Bug Hunt

Inspired by the price-alert storms that buzz phones at 3 AM — the same alert, five times, because the dedupe state was shared globally instead of tracked…

  • Language: Python
  • Layer: Backend
  • Difficulty: Easy
  • Concepts: Dedupe, State
  • Modelled on: Coinbase-class alerts
  • Visible tests: different users are independent; the same alert is suppressed within the window; the window expires
  • Reward: 50 XP for a complete fix

Briefing

Inspired by the price-alert storms that buzz phones at 3 AM — the same alert, five times, because the dedupe state was shared globally instead of tracked per user and per alert.

alerts.py rate-limits notifications: one per (user, alert key) per hour.

Bug report

BUG-BUZZ · Priority: High (app deletions) · Reported by: mobile

should_send(user, key, now, state):

  • send if this (user, key) pair has not fired within 3600 seconds
  • record the send time on success

Observed: ONE global timestamp for everything — after any alert fires, every other user's alerts are suppressed for an hour (and vice versa at reset).

Logs

[alerts] user_a BTC alert fired -> user_b's ETH alert suppressed

The code as shipped

src/notify/alerts.py (editable)

# Per-user, per-alert notification rate limiting.

WINDOW_SECONDS = 3600

def should_send(user, key, now, state):
    last = state.get("last_sent")
    if last is not None and now - last < WINDOW_SECONDS:
        return False
    state["last_sent"] = now
    return True

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Python bug hunts.