🕵️ SicherheitslückenCVE-2026-85014 | undici up to 7.29.0/8.10.1 Socket Close denial of service(16.09.2026 um 04:26 Uhr)
🕵️ SicherheitslückenCVE-2026-85014 | undici up to 7.29.0/8.10.1 Socket Close denial of service(16.09.2026 um 04:26 Uhr)

🔧 Programmierung 🕛 vor 3 Monaten 2 Min Lesezeit
0

Testing OTP email flows shouldn't be flaky — meet AssertKit

↗ Quelle (dev.to)
🗣️ Stimme:

The single most flake-prone test in any E2E suite is "user signs up,

verifies via emailed OTP, completes onboarding." Why? Because the email

is async, the test runner can't see it, and the bridge between the two

is a 60-line polling helper everyone writes once and nobody wants to

maintain.



I shipped AssertKit to remove that bridge entirely.



The pitch in 8 lines of test code:




CODE
  import { test } from "@assertkit/playwright";

test("signup with OTP", async ({ page, inbox }) => {
await page.goto("/signup");
await page.getByLabel("Email").fill(inbox.address);
await page.getByRole("button", { name: "Sign up" }).click();
const otp = await inbox.waitForOtp({ from: "noreply" });
await page.getByLabel("Code").fill(otp);
});






That's it. No polling. No regex. No flake.



How it works




  1. The inbox fixture gives every test a unique disposable address
    (



    The demo opens a real long-poll against the real wait endpoint. A

    canned email arrives 3 seconds later. You'll see the OTP land in real

    time.



    Free to try:




    • Both npm packages are MIT, zero runtime deps

    • The free public API works without an account

    • Subscriptions aren't open yet — there's a /beta program for early
      access with admin approval



    Tech stack (if anyone's curious): Next.js 16 App Router, Drizzle +

    Neon Postgres, Supabase Realtime for sub-100ms broadcast, CloudMailin

    for inbound MX, Resend for outbound (DKIM-signed), Upstash KV for

    rate limits, argon2id + RFC 6238 TOTP for auth.



    Solo founder, happy to answer anything.

    Vollständiger Original-Artikel
    Den kompletten Beitrag mit allen Details direkt auf dev.to lesen.
    ↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
7 Quellen
CVE-2024-44965 | Linux Kernel up to 6.10.4 pti_clone_pgtable stack-based overflow (Nessus ID 208953 / WID-SEC-2024-2057)
3 Quellen
CVE-2026-84961 | undici up to 7.29.0/8.10.1 BalancedPool BalancedPool constructor connect/tls certificate validation
3 Quellen
CVE-2026-84657 | Jenkins up to 2.567.x CLI permission
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Testing OTP email flows shouldn't be flaky — meet AssertKit

Thematisch verwandte Begriffe: Testing, email, flows, shouldnt · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...