Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
IT Security Toolsconpot v1.0.0(21.09.2026 um 07:32 Uhr)
IT Security ToolsZircolite v4.0.0(21.09.2026 um 08:27 Uhr)
IT Security NachrichtenWaterPlum Hackers Steal $10.7M in Crypto From IT Workers(21.09.2026 um 08:52 Uhr)
Sicherheitslücken (CVE)Die größte Schwachstelle sitzt am Schreibtisch - kommunal.at(21.09.2026 um 07:36 Uhr)
IT Security NachrichtenIT Security News Hourly Summary 2026-09-21 08h : 6 posts(21.09.2026 um 08:00 Uhr)
IT Security Toolsconpot v1.0.0(21.09.2026 um 07:32 Uhr)
IT Security ToolsZircolite v4.0.0(21.09.2026 um 08:27 Uhr)
IT Security NachrichtenWaterPlum Hackers Steal $10.7M in Crypto From IT Workers(21.09.2026 um 08:52 Uhr)
Sicherheitslücken (CVE)Die größte Schwachstelle sitzt am Schreibtisch - kommunal.at(21.09.2026 um 07:36 Uhr)
IT Security NachrichtenIT Security News Hourly Summary 2026-09-21 08h : 6 posts(21.09.2026 um 08:00 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Tests Should Buy Confidence, Not Become the Feature

Reagiere als Erste:r — dein Feedback zählt!

While implementing the Job Opportunity creation workflow in my Candidate Tracker, I reached an uncomfortable point: the application-service tests felt harder to understand than the feature itself.

The production workflow was small:

  1. Validate and normalize the submitted input.
  2. Confirm that the selected Company exists.
  3. Create the Job Opportunity.

The tests introduced much more vocabulary and setup: fixtures, fakes, spies, mocks, controlled failures, and assertions that certain repository methods were never called.

That complexity is not automatically a problem. A test must construct the world in which a behavior runs. However, it made me reconsider what each test was actually buying.

The tests I kept

I kept three application-service cases:

  • valid input is normalized and created;
  • invalid input stops before persistence;
  • a missing Company does not create an orphan opportunity.

These cases protect business decisions. If any of them breaks, the application can accept invalid data or violate an important relationship.

The tests I did not add

The service also forwards failures returned by repositories. I could mock every repository method and test every forwarding branch, but those tests would mostly prove that:

if (!result.success) return result;


{data-source-line="157"}

returns the same result it received.

That behavior is already constrained by TypeScript, while real PostgreSQL integration tests verify persistence behavior. The complete browser workflow was also checked manually.

Adding more mocks would increase the test count, but not necessarily my confidence.

Choosing the right testing level

My current rule is:

  • unit-test business rules and meaningful decisions;
  • integration-test actual persistence behavior;
  • verify the complete user workflow;
  • add regression tests when real bugs reveal a missing case;
  • do not optimize for test count or branch coverage alone.

This is not an argument against testing. It is an argument for making every test justify its maintenance cost.

Tests should reduce the fear of changing code. When the setup becomes harder to understand than the protected behavior, the testing level or scope may need simplification—not necessarily the feature.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Tests Should Buy Confidence, Not Become the Feature

Thematisch verwandte Begriffe: Tests, Should, Confidence, Become · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-94030 | A security vulnerability has been detected in SerenityOS up to 3d83e4509…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick