ebook

Denteractive teledentistry security and crucial business flow issues - audit and implementing fix

The client's traffic grew significantly due to COVID. Via Denteractive's app patients with a medical emergency can request an immediate video consultation with a dentist

  • A significant issue where multiple dentists were assigned to the same issue causing confusion and significantly higher costs as each dentist was expected to be compensated for the tele-consultation.
  • There were additional security and codebase issues that needed to be addressed

Project scope

Backend servicesSolving an issue tied to business operations

Assessment & Improvementsof backend logic

Xfaang Outcomes
& Solutions

  • We audited the product
  • We applied a fix to this specific race condition by applying locking on the database level and applied defensive coding practices
  • The solution was thoroughly tested via pentests and is confirmed to comply with all the corporate security requirements

Needed solution:

    The problem caused Denteractive to book multiple dentist appointments for the same user

  • They where therein obligated to pay each dentist for this visit, despite patients only needing one
  • The code base and security issues involved were at risk of a potential leak, a significant concern when considering the sensitivity of patients' medical records

We were provided with:

  • Access to the code repo and production server
  • The problem was brought to our attention, but we had to diagnose and repair the problem on production. This was a very delicate process due to working on a live product that included payment functions.
  • Tech stack:
    • Framework - RoR
    • Language - Ruby
    • Server - AWS
    • Websockets
    • Postgresql

Tools

Slack

    Jira

      Gitlab