Post #2243549
2026-04-27 16:43 UTC
Well into blame we get:
"The Railway GraphQL API allows volumeDelete with zero confirmation.
A single API call deletes a production volume. There is no "type DELETE to confirm." There is no "this volume is in use by a service named [X], are you sure?" There is no rate-limit or destructive-operation cooldown. No environment scoping. Nothing between an authenticated request and total data loss."
I'm like -- well, it was a POST operation with the API key, not a UI. I don't know what to tell you
Replies (2)
-
@platypus@glammr.us 2026-04-27 16:44
"Railway markets volume backups as a data-resiliency feature. But per their own docs: "wiping a volume deletes all backups."" ... ok yeah, that is on Railway, but um... also on anyone using it???
-
@adr@mastodon.social 2026-04-27 16:46
@platypus@glammr.us yeah this one sort of stank to me too. If there aren't defined roles in Railway that limit access by role -- like if every user in Railway is effectively root, then yes, that's bad. But saying "Railway should have thrown up a "type DELETE to confirm""??? that is nonsense. To me this smells like they just gave Claude unsupervised root on a thing and are ass-covering. dumb.