anthropics / anthropics/claude-code

Ran a destructive tinker/migrate:fresh command against the live app DB instead of an isolated test DB

オープン
#90,808 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
area:bash area:permissions data-loss duplicate platform:windows
主要言語
Python
スター
145k
フォーク
23.1k
PR マージ指標
PR 指標を取得中

説明

While debugging inside a Laravel project, Claude Code (main agent loop, not a subagent) ran `php artisan tinker` scripts to inspect and fix data live, and at one point ran `migrate:fresh` inside one of those scripts to get a "clean slate" for reproducing a bug. It treated this as safe/isolated debugging.

It was not isolated. The project's `phpunit.xml` correctly points `php artisan test` at an in-memory SQLite DB, but there is no `.env.testing` file, so `tinker` and `migrate --env=testing` both silently fall back to the real `.env` and hit the actual live database. `migrate:fresh` drops every table. This wiped real user data (accounts, shift records, personnel records, leave applications, protocols, etc.) down to almost nothing. It was only partially recoverable from a stale backup, permanently losing roughly 1.5 days of real work.

This is the second time this specific failure mode has happened in this project. There was no explicit confirmation step before the destructive command ran -- the model reasoned it was acting on a disposable/isolated database and proceeded without pausing to check.

Suggested improvements:
- Before running `migrate:fresh`, `migrate:rollback`, `db:wipe`, or a `tinker` script containing writes/deletes, more strongly weigh whether the target could be a live database, especially when no `.env.testing` is present to prove isolation.
- Treat `tinker` as no less dangerous than raw SQL by default, not as a "safe debugging" tool.

Environment: Windows 11, Laravel + SQLite, Claude Code CLI (main session, Sonnet 5).

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

調査の方向性

Start by tracing the Claude Code main agent loop that executes shell commands, using the reported `php artisan tinker` and destructive migration commands as the reproduction path. Review how the absence of `.env.testing` and the project’s `phpunit.xml` affect isolation. Done means risky database operations and write-capable tinker scripts identify possible live targets and require explicit confirmation before execution.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
laravel, php, sqlite
領域
cli, databases, security
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
活発
明瞭さ
おおむね明確
初心者へのやさしさ
45/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。