But the employer wanted a full-stack developer, everything else is just details!
I’ve seen worse code than this. How about a hard coded backdoor check that looked like: || pw == “debug0”
I’ve seen worse code than this. How about a hard coded backdoor check that looked like: || pw == “debug0”
(initially I had a 'superuser' permission that would sort of short-circuit the permission system, but I felt really uncomfortably about how much that affected my code. I figured having compile-time hard-coded superusers per-app-instance would make more sense).
Yes
> and how to do it better.
Put these users/passwords in the database like all the other users so that you can shut them down when the passwords leak to the public.
If you have to do it then accept it as a command-line argument or read it from a config file - at least then it can be backed-out with an application restart instead of a recompile.