Technical notes on web development, DevOps, and AI integration.
1 article
Automating development login through the real form submit plus a fail-closed env guard: fast, with no backdoor left behind in production.
TL;DR: Repeated manual logins for testing were exhausting, and injecting tokens to bypass the form broke app state and caused flaky tests. Instead, automating the actual form submission behind an explicit opt-in env variable keeps it off by default. Paired with role-limited dev users and separate config, it speeds up testing without opening security holes in production.