Hacker News new | ask | show | jobs
by wmichelin 167 days ago
your test environment should not have the credentials to write to prod data. yiiiiikes!
1 comments

Credentials end up existing in prod because the person used Mochito and didn’t override the function for providing credentials :’c
Credentials should only be provided at the application root, which is going to be a different root for a test harness.

Mockito shouldn't change whether or not this is possible; the code shouldn't have the prod creds (or any external resource references) hard coded in the compiled bytecode.

I totally agree, I’m being tongue in cheek, but given how poor some codebases can be, the more precautions the better ie compilation failures on non-mocked functions.