Computer
The Big Refactoring Update
Today's anonymous submitter spent a few weeks feeling pretty good about themselves. You see, they'd inherited a gigantic and complex pile of code, an application spread out across 15 backend servers, theoretically organized into "modules" and "microservices" but in reality was a big ball of mud. And after a long and arduous process, they'd dug through that ball of mud and managed to delete 190 files, totaling 30,000 lines of code. That was fully 2/3rds of the total codebase, gone- and yet the tests continued to pass, the application continued to run, and everyone was just much happier with it.
Two weeks later, a new ticket comes in: users are getting a 403 error when trying to access the "User Update" screen. Our submitter has seen a lot of these tickets, and it almost always means that the user's permissions are misconfigured. It's an easy fix, and not a code problem.
Just to be on the safe side, though, they pull up the screen with their account- guaranteed to have the right permissions- and get a 403.
As you can imagine, the temptation to sneak a few fixes in alongside this massive refactoring was impossible to resist. One of the problems was that most of their routes were camelCase URLs, but userupdate was not. So they'd fixed it. It was a minor change, and it worked in testing. So what was happening?
Well, there was a legacy authorization database. It was one of those 15 backend servers, and it ran no web code, and thus wasn't touched by our submitter's refactoring. Despite their web layer having copious authorization and authentication code, someone had decided back in the olden days, to implement that authorization and authentication in its own database.
Not every request went through this database. It impacted new sessions, but only under specific conditions. But this database had a table in it, which listed off all the routes. And unlike the web code, which used regular expressions for checking routes, and were case insensitive, this database did a strict equality comparison.
The fix was simple: update the table to allow userUpdate. But it also pointed towards a deeper, meaner target for future refactoring: dealing with this sometimes required (but often not!) authentication step lurking in a database that no one had thought about until our submitter's refactoring broke something.
[Advertisement] ProGet’s got you covered with security and access controls on your NuGet feeds. Learn more.Technology For Lab-Grown Eggs Or Sperm On Brink of Viability, UK Watchdog Finds
Read more of this story at Slashdot.
'Ghost' That Haunts South Carolina Rail Line May Be Caused By Tiny Earthquakes
Read more of this story at Slashdot.
Record $4.5 Billion EU Fine Punished Its Innovation, Google Tells EU Court
Read more of this story at Slashdot.
White House 'Looking Into' National Security Implications of DeepSeek's AI
Read more of this story at Slashdot.
OPM Sued Over Privacy Concerns With New Government-Wide Email System
Read more of this story at Slashdot.
White House Says New Jersey Drones 'Authorized To Be Flown By FAA'
Read more of this story at Slashdot.
Boom Supersonic XB-1 Breaks Sound Barrier During Historic Test Flight
Read more of this story at Slashdot.
Apple Chips Can Be Hacked To Leak Secrets From Gmail, ICloud, and More
Read more of this story at Slashdot.
Hugging Face Researchers Are Trying To Build a More Open Version of DeepSeek's AI 'Reasoning' Model
Read more of this story at Slashdot.
FCC Will Drop Biden Plan To Ban Bulk Broadband Billing For Tenants
Read more of this story at Slashdot.
Pay Raises Are Shrinking in 2025, CFOs Say
Read more of this story at Slashdot.
LinkedIn Removes Accounts of AI 'Co-Workers' Looking for Jobs
Read more of this story at Slashdot.
Atomic Scientists Adjust 'Doomsday Clock' Closer Than Ever To Midnight
Read more of this story at Slashdot.
UK Considers Making Netflix Users Pay License Fee to Fund BBC
Read more of this story at Slashdot.
Garmin Users Say Their Watches Are Bricked With a 'Blue Triangle of Death'
Read more of this story at Slashdot.
Google To Cut Off Chrome Sync for Older Browser Versions
Read more of this story at Slashdot.
Cloud Services Market Is 'Not Working,' Says UK Regulator
Read more of this story at Slashdot.
Bookshop Takes On Amazon With E-book Platform For Independent Stores
Read more of this story at Slashdot.
DeepSeek Has Spent Over $500 Million on Nvidia Chips Despite Low-Cost AI Claims, SemiAnalysis Says
Read more of this story at Slashdot.