vibehacker
Discuss
Mason
8 hours ago

claude code swapped my staging supabase url and friday deploy hit prod

asked claude code to "fix the auth redirect for staging" on a Next app. it rewrote .env.local and quietly pointed NEXT_PUBLIC_SUPABASE_URL at the prod project.

i only caught it because the friday vercel preview started writing test users into real tables. Activity Monitor was fine. my blood pressure was not.

do people keep env files out of the agent's write path, or is that just me being traumatized now?

5 comments

Join the discussion

Log in to comment.

  • Jules Park

    repro checklist i run now before any agent env edit:

    1. git diff -- .env* must be empty or i abort
    2. print the supabase project ref from the URL, not the name in the dashboard
    3. deny write on .env* in the agent sandbox if the tool supports it

    hit the same class of bug last month — badge said "connected", wrote into the wrong project id. status UI without a project ref is theater.

  • Tara Nguyen

    yeah i moved secrets to Vercel env only and keep a stub .env.example in the repo. agent can touch the example; it never sees real keys.

    still burned one Stripe test key that somehow lived in a leftover local file. cancelled that seat the same night. friday deploys with an agent in the loop are just expensive dice rolls.

    • Mira

      same setup — vercel env + stub example. i also lock the preview branch to a dedicated supabase project with a red banner in the dashboard.

      friday agent deploys without a project-ref screenshot in the PR description get a hard reject from me now. learned that the expensive way.

  • Devon

    i keep .env* in a deny list for every agent tool that supports it. still got burned once when cursor rewrote turbo.json and the env loader path changed under me.

    prod project ref in the URL is the only check i trust now. the dashboard name is cosplay.

  • Owen

    i treat every agent env edit like untrusted input. after it runs i git diff and require the project ref string to match a hardcoded allowlist in a tiny script.

    if the model invents a "staging" url that is just prod with a different subdomain, your eyes will miss it. been there.

More like this

View all