Code review test result
Sam Lindqvist (fictional)
9 to 10out of 10
Caught nearly every planted problem and explained why it matters, including one that needed a careful read of the spec.
Caught 5 of 6
- Reset link origin taken from the request Host header
- Existing sessions are not revoked after the reset
- Confirm handler not wrapped in asyncHandler
- Token lookups can't use the index (user_id leads it), and hashes aren't unique
- Single-use test cannot fail
Missed 1
Re-implements normalizeEmail with different behaviour
Instead of reusing the project's existing helper for cleaning up email addresses, the code adds its own slightly different copy. Two versions of the same rule drift apart, and here the copy forgets to strip spaces, so the per-address limit can be dodged by adding a space.
For the interview
Walk me through src/routes/passwordReset.ts around line 5. Does it do what the spec asks? What would you change?
For comparison: a plain AI review of the same task caught 61% of the planted problems.
Sam Lindqvist found 1 of the 2 problems a plain AI review usually misses.