Someone Else's Bank Account — JavaScript Bug Hunt

Modelled on the TSB Bank migration (April 2018): moving 1.3 billion customer records onto a new platform, records were re-keyed incorrectly and customers…

  • Language: JavaScript
  • Layer: Database
  • Difficulty: Medium
  • Concepts: Migration, Identifiers
  • Modelled on: TSB Bank · 2018
  • Visible tests: accounts attach to the right customer; an account with no customer is marked UNKNOWN
  • Reward: 50 XP for a complete fix

Briefing

Modelled on the TSB Bank migration (April 2018): moving 1.3 billion customer records onto a new platform, records were re-keyed incorrectly and customers logging in were shown other people's accounts and balances. The outage ran for weeks and cost the bank around £330 million.

migrate.js re-keys accounts during the move and joins on the wrong field.

Fix migrateAccounts so every account stays with its own customer.

Bug report

BUG-TSB18 · Priority: Critical (data integrity) · Reported by: migration control

migrateAccounts(legacyAccounts, customers) must return, for each account, { accountId, customerId, name } where the name is the name of the customer whose id matches the account's customerId.

Observed: accounts are matched to customers by array position instead of by id. Because the two lists are not in the same order, customers see each other's accounts.

Logs

[migrate] account acc-2 (customerId cust-9) attached to name="Priya Nair" (cust-3)
[migrate] 21403 mismatched attachments in this batch

The code as shipped

src/migration/migrate.js (editable)

// Attaches each legacy account to its customer.
exports.migrateAccounts = function (legacyAccounts, customers) {
  var out = [];
  for (var i = 0; i < legacyAccounts.length; i++) {
    var acc = legacyAccounts[i];
    // The two extracts were exported together, so position i lines up.
    var customer = customers[i];
    out.push({ accountId: acc.accountId, customerId: acc.customerId, name: customer.name });
  }
  return out;
};

Read-only context: src/migration/EXTRACT.js.

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.