“It Worked” Is Not “It’s Fixed”: What a PKCE Auth Bug Taught Me About QA-ing AI-Generated Code
中文摘要
探讨 AI 生成代码的 QA 挑战,通过 PKCE 认证漏洞强调“运行成功”不等于“问题修复”,提醒在金融等关键系统中使用 AI 时需严谨测试。
English Summary
Using a PKCE auth bug example, the author warns that "it worked" isn't "it's fixed," emphasizing the need for rigorous QA when testing AI-generated code.
Original Excerpt
I’ve spent ten years testing payments and fintech systems — the kind where a login bug isn’t an inconvenience, it’s a support ticket, a… Continue reading on Medium »