* No authentication check on any page after login page. (You could type in any URL in browser address bar and gain access).
* GET request updating home page related content in database. (A few of these GET request was picked up by Alexa bot and we hard our home page content change randomly for many days. We had a real hard time troubleshooting this one).
* Use of mysql_query() in PHP. (Deprecated mote than 10 years ago. Opens doors for SQL injection).
* Use of loop variables i,j,k,l,m for 5-level nested loop. (Too error prone and difficult to read).
* Unit testing applied to a highly monolithic code. (The hacks for isolating code units produced more garbage than the code itself). It was a legacy code and the management blindly ordered writing of unit tests when a few bugs were caught in production.
Do you (or indeed anyone else reading) have suggestions for getting other forms of testing in place around legacy monolithic code?
Perhaps this is a fairly ill-posed question without more context.
Later, the user complained about all of their photos constantly being deleted.
Photo deletes were GET-based and did not have no-follow. Google eventually indexed their logged-in link and was happily deleting all of their photos daily.
Fun times tracking that one down. (It was a code base that I inherited.)
public class ScoreManager {
//some statements
public void updateScore(Action action) {
int n = action.entityDestroyed;
if n < n1 {
playSound1();
score += 100*n;
} else {
playSound2();
score += 200*n;
}
}
}
I had to deal with that piece of code for something, and asked the developer to move the functions playing the sound out of the ScoreManager class so I could reuse it, and he categorically refused without giving me any explanation.EDIT: typos
Even worse... I wrote the code. It was 2am, I had been working for 18 hours straight to get everything ready for a demo the next morning.
Even worse than that... the code worked so management wouldn't let me change it. I tried my best to find an edge case it wouldn't handle but never could. So the code shipped.
> Functions with about 16 parameters.
I am reminded of a talk by Kevlin Henney [1]. He mentions this quote from Alan Perlis: "If you have a procedure with ten parameters, you probably missed some." [2]. Kevlin goes on to give anecdotes about code he has encountered or heard stories about while consulting / teaching - the record was a function with around 370 parameters, and that function was still growing.
I'd prefer to see a function with a dozen arguments than a "function" that takes no arguments, returns void, and secretly communicates using global state. Explicit horror beats surprise horror.
[1] http://www.infoq.com/presentations/architecture-uncertainty-... [2] http://www.cs.yale.edu/homes/perlis-alan/quotes.html
The returned string had the info a customer concatenated, like this:
Pete McDonald 5519500303
The instructions - to extract the data - were: The indexes from 0 to 9 will contain the name (please trim the trailing spaces)
The indexes from 10 to 19 will contain the last name (same, please trim)
20 to 21 will contain the age of the customer
the rest of the string contains the customer's birthday
EDIT: formatting"I don't know why this works"
Oops. After that they put me at the front end due diligence instead of the back end.
And now think about the security and data integrity problems that implies.
Not that many years ago I was still seeing people storing credit card numbers in plain text files on servers, and sending them unencrypted via email.
I've seen it in the last week. I work for an ESP, and have to continually tell customers "just because you can store CCs (or SSNs, or private account #s, etc) in our database, there's never a good reason why you should" and "PCI? Heard of it?".
- duplicating full data set to handle offline sync of data between a client and a server
- over 1000 lines of java per source file
Edit: formatting
RPG.
Sorting months by alpha name.