Skip to content

Comment on Gitlab – Static passwords set during OmniAuth-based registration (CVE-2022-1162)parent

Comments

Right, but you can bypass that in a testing environment.

Which then opens you up to exactly that class of bugs that also caused this issue. Having test specific code and feature flags and then testing a tweaked version isn't really covering all the cases then.

Just like in this case where a hardcoded password was set to maybe log in through a test based on the naming "test_default".

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.