|
From: James F. <jam...@gm...> - 2010-03-24 19:30:24
|
On Wed, Mar 24, 2010 at 8:11 PM, Dmitriy Shabanov <sha...@gm...> wrote: > On Wed, 2010-03-24 at 20:03 +0100, James Fuller wrote: >> Dont forget, its easy to add xquery level unit tests now as well aka >> eXist/test/src/xquery > > I do not believe to unit tests as you do :-) > (especially in security area) testing (of all types) is one of the few techniques one can employ to achieve good security characteristics in software ... but if you have any other new techniques on the matter, I would love to hear ... I know the answer isn't 'write perfect code' because I have been trying that for 25 years with little success. I don't believe in unit tests as some magic bullet, but at a minimum they do a good job at explaining assumptions a few months/years from now (e.g. those hard coded paths). otherwise, back to the thread ... Dannes needs to be satisfied that all is well with this stuff and as I understand it he isn't because he raised a list of concerns which have yet to be addressed. J |