Reminds me of my most customer-visible screwup.
- Implement rate limiting on a site to deal with scrapers
- Include the https://http.cat/429 in the template for 429 responses.
- Time passes
- Implement API for displaying an information widget in customer company’s own website (big pharma regent suppliers), content get injected as an iframe loaded from our site.
- Customer employees all visit their own website from behind a reverse proxy with the same IP, trigger the (poorly configured) rate limiting
- Panicky customer contact: “Why is your widget displaying cat pictures on our website and could you please stop it right now”
This now forms a key foundation in my “no whimsy in code” rule along with one or two near misses with dummy data/content.