2 ms·
> Note that host is hardcoded to localhost. This means it should never connect to any machine other than the developer machine. Just to help with the postmorte
by 0kl 6y ago
> Note that host is hardcoded to localhost. This means it should never connect to any machine other than the developer machine.
Just to help with the postmortem:
1) “localhost” is just a loopback to whatever machine you’re on
2) the user and pw are pulled from config
So someone was running this from the production server or had the production DB mapped to localhost and ran it with a production config for some reason (working with prod data maybe). The hard coding to localhost will only ensure that it works for the machine it’s called on - in this case the prod server.
Things you might do to avoid this in the future include a wide spread of things, the main recommendations I’d have are:
1) only put production artifacts on prod
2) limit developer access to prod data
Best of luck