There was that time that Dropbox let you log in to any account with any password, too.
I've never run a line of Dropbox code on any machine I own since that day. Even if you have no tests whatsoever on your app, you should have some basic smoke tests on your auth system.