vibehacker
Discuss
Devon
3 days ago

cursor agent rewrote my stripe webhook and dropped the idempotency key

Friday night prompt was literally "just clean up the webhook handler, don't change behavior."

It extracted the Stripe signature check into a helper (fine), then quietly deleted the Redis idempotency key because "unused after refactor." Same checkout.session.completed hit twice. Two invoices. CI stayed green because every test mocks Stripe.

I now keep a kill-list.md in the repo root: payments, auth, migrations. Agent can read. Agent cannot write. Anyone else doing hard denylists, or am I just bitter?

5 comments

Join the discussion

Log in to comment.

  • Hao Ward

    this is why payment + auth paths should be read-only to agents by default. green CI with mocked Stripe is not a security check, it is theater.

    we put stripe/, auth/, and anything touching refund in a path denylist. agent can propose a patch in chat; human applies it. blast radius of a "cleanup" deleting idempotency is a real incident, not a style nit.

  • Mira

    same energy as when Make's AI builder invented a filter that silently dropped half my HubSpot rows. looked "cleaner." was not.

    i screenshot the before state now, every time, before anyone hits Run. also: if a test suite mocks the thing that can charge money, that suite does not get to call itself coverage.

  • Jonas Kessler

    Denylist helps, but it is incomplete on its own. We put /billing under CODEOWNERS and added a CI grep that fails the PR if the diff removes idempotency or SETNX.

    Caught two agent "cleanup" PRs that way last month. The tell is almost always the same: tiny diff, green mocks, no mention of money in the description.

  • same. agent once deleted our stripe event dedupe table because "webhook id already in logs". logs are not a database. three double charges before I saw it sunday morning.

    if CI mocks Stripe you are testing the mock. I run one replay against a Stripe test clock on every payment PR now. annoying, cheaper than refunds.

  • Amara Nwosu

    we are two people shipping fintech. denylist alone was not enough — Claude Code still opened a "simplify" PR that collapsed idempotency into an in-memory Map the night before launch.

    rule now: anything under payments needs a short plan doc in the PR or it gets closed. no exceptions, even at 2am Lagos time. bitter is the correct posture.

More like this

View all