How a Node.js Bridge Connects MAX and VK Messengers to Chatwoot with Secure Bidirectional Sync
A technical walkthrough details the construction of a bidirectional bridge that integrates the MAX messenger and VK communities into Chatwoot as separate API inboxes. The solution avoids web scraping and personal account automation by relying exclusively on official bot endpoints and community callback mechanisms.
The architecture consists of a minimal Node.js service exposing four webhook routes: incoming events from MAX, VK Callback API confirmations and messages, plus protected outgoing routes triggered by Chatwoot message_created events. All traffic terminates at a reverse proxy while the container itself remains isolated on an internal Docker network.
Contacts are created with stable identifiers prefixed by channel (max: or vk:) to prevent cross-platform collisions. Conversations are then linked via source_id returned by the Chatwoot Application API, and mappings are persisted in a JSON file inside a named Docker volume to survive container restarts.
Incoming MAX messages are authenticated using the X-Max-Bot-Api-Secret header and filtered to exclude bot-generated updates. VK events undergo group_id and secret validation, with only message_new events processed. Photographs from VK are downloaded at maximum resolution and forwarded as multipart attachments.
Outbound messages from Chatwoot are filtered to ensure only genuine operator replies are relayed. MAX messages use the platform-api2 endpoint with Authorization tokens supplied via mounted secrets. VK image uploads follow the three-step photos.getMessagesUploadServer, upload, and photos.saveMessagesPhoto flow.
Deduplication relies on message IDs stored in limited ring buffers of the last 2000 events. The author notes that this provides protection against duplicate webhooks but does not guarantee exactly-once semantics. SSRF risks are mitigated by enforcing HTTPS, exact origin matching for Chatwoot URLs, MIME-type restrictions, size limits, and redirect validation.
The implementation is packaged as a minimal Alpine-based Docker image running as an unprivileged user. Production recommendations include replacing the JSON state file with a transactional database, adding a durable queue with dead-letter handling, and implementing structured logging plus rate-limit awareness.
Related articles
NtechLab AI Video Analytics Helps Locate 250 Missing Children in Novosibirsk Region
NtechLab has reported that its generative AI-powered video analytics platform assisted Russian law enforcement in finding 250 missing children in the Novosibirsk region in less than 18 months. The FindFace Multi system operates as part of the Safe City complex and processes live video feeds from cameras installed at transport hubs, streets, squares, and government buildings. Facial recognition capabilities for locating children became available to regional authorities in April 2025. The same technology has also been used to identify more than 3,000 offenders throughout 2025. NtechLab states that its solutions are deployed across more than 70 Russian regions and 34 countries, although the company provided no detailed breakdown of individual cases or average search times. All final decisions and physical searches remain the responsibility of human police officers.
RemoveMacAI Utility Appears on GitHub to Disable Apple Intelligence and Free Disk Space on macOS
A new open-source tool called RemoveMacAI has been released on GitHub, allowing macOS users to fully disable Apple Intelligence features and remove associated AI models from their systems. The utility addresses the lack of a single toggle in macOS 27 for turning off generative AI capabilities while also reclaiming storage space occupied by downloaded models. It supports Apple silicon devices and works by leveraging Apple's own system services rather than directly modifying protected directories. Users can selectively disable components such as Siri, Writing Tools, Genmoji, Image Playground, ChatGPT integration, smart replies, photo cleanup, and Xcode predictive code completion. The tool also installs a configuration profile that prevents models from being redownloaded automatically. Reversion is possible via the removemacai revert command, though this comes at the cost of losing access to certain Apple Intelligence-powered functions in third-party apps and Shortcuts. The project is licensed under MIT and leaves Dictation untouched as it is managed separately.
Secure Personalization of Java Card Applets Using Issuer Security Domain and SCP02
The article explains how to leverage the Issuer Security Domain mechanisms on GlobalPlatform cards to establish secure channels for applet personalization without implementing custom ECDH-based key exchange. It addresses limitations of prior approaches that lacked authentication and required extensive PKI support. The solution uses SCP02 with specific security levels such as C_MAC and C_DECRYPTION to protect commands that store AES-128 keys and personal data on the card. Detailed code walkthroughs cover the applet constructor, process method, mutual authentication via SecureChannel.processSecurity, and unwrap operations for decrypting and verifying APDUs. Practical testing on NXP Java Cards demonstrates installation via FunGP library scripts that allow configurable security levels during mutual authentication. The implementation ensures that secret key updates enforce C_DECRYPTION while personal data writes accept C_MAC, with encrypted reads performed using AES-CBC.
IT Jobs at Major Tech Firms Turn Into Dating Red Flags for Some Women
Working in IT used to be seen as a strong advantage in dating due to high salaries and prestigious employers. However, employees at companies like Palantir and Tesla now report that their jobs trigger uncomfortable conversations about ethics and politics instead of romantic interest. A Palantir engineer named Gary has started hiding his employer after facing sharp reactions from women and even requests from friends to avoid mentioning the company at social events. Tesla employee James encounters questions about his political views simply because of his association with Elon Musk's company. Dating specialist Amy Laurent notes that tech giants face backlash over issues like surveillance, inequality, and AI displacing workers, forcing professionals to present their careers with caveats. The article from Wired highlights how an employer's reputation now overshadows individual values during initial meetings. While IT roles remain attractive in many ways, the automatic boost from big tech brands appears to be fading in personal contexts.