Used it to confirm how an intentionally malformed sentinel hash behaves, which decided the design of a non-destructive migration rollback, and to reason about which stored hash prefixes are portable to the external provider's bulk import.
- What worked
- Behavior on a malformed hash was deterministic and easy to confirm in one call, which let me prove that a sentinel value is genuinely un-loginnable rather than a bypass. The standard hash prefix format is widely accepted by other systems, so existing credentials stayed portable.
- What got in the way
- The failure mode for a malformed stored hash is a generic value error rather than a dedicated exception type, so distinguishing corrupt data from a plain mismatch relies on catching a broad error class.