Cursor deleted my Pinia refund path and CI still passed
Friday afternoon, MacBook Pro, Cursor on Claude. I asked it to "clean up the Pinia checkout store" before a client demo.
It deleted refundOrder(), flattened three actions into one giant mutateCart, and left a comment that said "simplified for readability". CI stayed green. Staging chargebacks did not.
Caught it in code review at 6:40pm. Rolled back, ate tacos, rewrote the refund path by hand. Anyone else gate agent edits on payment/auth files, or am I just scarred now?

5 comments
Join the discussion
Log in to comment.
We treat payment + auth dirs as agent-readonly now. Cursor can read them, propose a patch in a side branch, but Accept All is blocked by a local hook that greps for
stores/checkoutandrefund.Still not perfect — last month it renamed
refundOrdertocleanupCart"for clarity" and our unit tests mocked the new name. Green CI, angry Stripe. The fix was a smoke test that imports the real export by exact name. Painful. Worth it.Yeah, treat money paths like schema migrations. I keep a CODEOWNERS-style list for agents: anything touching payments, auth, or Kafka produce gets a hard human review, no Accept All.
Also worth a tiny smoke test that asserts refundOrder still exists after refactors. Green CI with a deleted function is the worst kind of green.
scarred is the correct emotional state tbh
i keep a denylist in
~/.cursor/agent-deny— anything under**/payments/**or**/pinia/**/*refund*gets a hard stop. agent still tries. terminal just says no.also: one assertion that
refundOrderstill exists after every "cleanup". if that test isn't there, CI is lying to you.Same class of bug as when agents strip labels "for cleanliness". Pretty checkout, broken refunds.
I've started pasting a one-liner into the prompt: do not delete exported functions used outside this file. Still fails sometimes, but less often than Friday-afternoon vibes.
This is a security incident dressed as a refactor.
Deleted refund path + green CI means your tests never exercised the money path. I would treat that store as tainted until you have: (1) exact-name export checks, (2) a Stripe test-mode chargeback replay, (3) agent write blocked on payment files.
We lost ~$1.2k in a weekend to the same class of bug on Win11 + Cursor. Friday afternoon vibes are expensive.