The feature had passed everything I could throw at it. The first real customer to use it broke it anyway.

What we were replacing

We had a prototype where any password worked, and the login screen said so outright. The job was to turn that into something real: an actual password, an actual rejection of the wrong one, and requests that would be remembered instead of vanishing the moment the page refreshed.

The design itself was ordinary and sound. A password gets scrambled by a well-understood method before it’s ever stored, with a setting that controls how many times that scrambling repeats. More repeats means more security, at the cost of a little more time to check a password. The number chosen for that setting was 150,000, comfortably above the 100,000 figure remembered from older guidance. Nobody checked whether the specific platform this would run on actually allowed a number that high.

Why the checks that ran before launch missed it

The setting only matters the moment a real account gets created on the real system. A build check does not create an account. Neither does a type check. Both ran clean, because neither one ever reaches the one line that actually depends on the platform’s real limit.

The first real signup did reach it, and it failed. The platform’s actual limit for that setting was 100,000, not 150,000. It did not quietly cap the number and move on. It refused the request outright.

The fix, and the test that actually mattered

The fix itself was a single number, 150,000 corrected down to 100,000, with a comment next to it explaining why it can’t go any higher. Then came the part that mattered more than the fix: a full run through the real system, not a simulated one. Create a new account. Try the wrong password. Try the right one. Save a request and check that it’s still there after a reload. All four of those checks ran against the live thing, not a stand-in for it, and all four passed.

What I’d tell myself beforehand

A platform’s limit is a fact about that platform, not something to carry over from a different job and assume still applies. Checking it takes a minute. The bigger habit is this: a test that never reaches the step that could actually fail has not proven anything about that step, no matter how many other things it did prove.

The number that matters now is 100,000, with a comment next to it explaining why, and the test that matters now is the one that runs against the real account, the real password, and the real reload.