The suite drop_all()s every table before every test, and this box both serves the live app and holds the repo — so "just don't run tests in prod" is not a workable guard. Getting this wrong once already cost a production Codex. The existing check compared TEST_DATABASE_URL against settings.database_url. That has a real hole: two different spellings of the SAME database — `...@localhost/quantumancy` versus `...@127.0.0.1/quantumancy` — are different strings, so the comparison passes and every table is dropped. Added a second, name-based guard: the test database NAME must end in `_test`. That cannot be defeated by how the host is spelled, and it also catches a TEST_DATABASE_URL somebody set by hand to something live. Both proven by attacking them: - TEST_DATABASE_URL forced to the production URL -> refuses (guard 1). - Same database reached via 127.0.0.1 instead of localhost -> refuses (guard 2; guard 1 alone would have allowed this and wiped it). - A normal run still works: 43 tests pass and the live account that prompted this check is untouched afterwards. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
4.9 KiB
4.9 KiB