qa
Technical notes on web development, DevOps, and AI integration.
2 articles
- 18:56testing
The Two-Layer QA Report: Append-Only Sessions, Living Modules
Why end-of-day reconstructed QA reports fail, and how the two-layer format with machine-artifact-only numbers makes test evidence traceable.
TL;DR: A new testing rule fixes untraceable findings by requiring an append-only session report filled in live, with unique scenario IDs, machine evidence, and a test-data ledger. A living module file tracks contract changes in every commit. First session proved it: 31 scenarios, 27 PASS, all counts matched 13 database queries.
#qa#testing#dokumentasi - 18:56security
The ZAP Baseline: Zero Failures Is Not the Number That Matters
A passive ZAP baseline before a QA backfill wave: zero FAIL, four WARN, and a rule-level delta table proving the new OAuth surface added no alerts.
TL;DR: The ZAP baseline rerun after adding Google OAuth came back clean: zero FAIL, four WARN, 57 PASS. More convincing, every rule-level count versus the prior baseline dropped or stayed flat, verified from the JSON artifact. Since the scan was passive and unauthenticated, these results cover only public pages; admin and API surfaces need their own session.
#zap#security-testing#owasp