My barcode generator encoded whatever I gave it — the check digit is the scanner's only trust
Two months ago I added barcode symbologies to what had been a plain QR endpoint — code128, EAN-13, UPC-A. My test suite verified the images rendered and that my phone could decode them. It never occurred to me to ask whether the number was valid. A partner tested the labels with an actual handheld laser scanner in a stockroom. Every EAN-13 I'd generated beeped back 'invalid read'. Same image file…
Two months ago, the author expanded a QR code endpoint to support barcode symbologies such as code128, EAN-13, and UPC-A. The author performed a test suite to ensure that rendered images could be decoded by a phone camera app. However, they never considered verifying the validity of the generated numbers. A partner attempted to scan the generated EAN-13 labels using a handheld laser scanner in a stockroom.
Every label generated by the author beeped back an "invalid read" error, even though the same image file successfully decoded using a phone camera app. The root cause of this issue was straightforward: the author had appended a 0 to their internal SKUs, resulting in twelve-digit EAN-13 codes. The encoding library produced barcodes with consistent data, but incorrect check digits.
The author's phone scanner apps were forgiving, as their primary function is to decode something. In contrast, retail scanners verify the checksum and reject any incorrect codes. The author implemented a fix that included three rules: twelve digits should be treated as UPC-A, with a zero prepended and the correct check digit computed.
Thirteen-digit codes with an incorrect check digit should return a 400 status code along with the corrected digit in the error body, rather than encoding faulty data. Any other input should be rejected based on length. The author chose to enforce hard rejection over silent auto-correction, as the latter would simply create more problems elsewhere.
The author now validates input within the generator at https://x402.freeq.one/tools/qr_generator.html, ensuring that the check digit is audited before generating the barcode.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.