anthropics / anthropics/claude-code

Ran a destructive tinker/migrate:fresh command against the live app DB instead of an isolated test DB

Ouverte
#90,808 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
area:bash area:permissions data-loss duplicate platform:windows
Langage dominant
Python
Étoiles
145k
Forks
23.1k
Métriques de merge des PR
Métriques de PR en attente

Description

While debugging inside a Laravel project, Claude Code (main agent loop, not a subagent) ran `php artisan tinker` scripts to inspect and fix data live, and at one point ran `migrate:fresh` inside one of those scripts to get a "clean slate" for reproducing a bug. It treated this as safe/isolated debugging.

It was not isolated. The project's `phpunit.xml` correctly points `php artisan test` at an in-memory SQLite DB, but there is no `.env.testing` file, so `tinker` and `migrate --env=testing` both silently fall back to the real `.env` and hit the actual live database. `migrate:fresh` drops every table. This wiped real user data (accounts, shift records, personnel records, leave applications, protocols, etc.) down to almost nothing. It was only partially recoverable from a stale backup, permanently losing roughly 1.5 days of real work.

This is the second time this specific failure mode has happened in this project. There was no explicit confirmation step before the destructive command ran -- the model reasoned it was acting on a disposable/isolated database and proceeded without pausing to check.

Suggested improvements:
- Before running `migrate:fresh`, `migrate:rollback`, `db:wipe`, or a `tinker` script containing writes/deletes, more strongly weigh whether the target could be a live database, especially when no `.env.testing` is present to prove isolation.
- Treat `tinker` as no less dangerous than raw SQL by default, not as a "safe debugging" tool.

Environment: Windows 11, Laravel + SQLite, Claude Code CLI (main session, Sonnet 5).

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Piste de recherche

Start by tracing the Claude Code main agent loop that executes shell commands, using the reported `php artisan tinker` and destructive migration commands as the reproduction path. Review how the absence of `.env.testing` and the project’s `phpunit.xml` affect isolation. Done means risky database operations and write-capable tinker scripts identify possible live targets and require explicit confirmation before execution.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
laravel, php, sqlite
Domaine
cli, databases, security
Type d'issue
Bug
Difficulté
4/5
Temps estimé
3-5 jours
Activité
Active
Clarté
Plutôt claire
Accessibilité débutants
45/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.