{"record":{"id":"af95f389edd307cf","repo":"clockworklabs/SpacetimeDB","slug":"publish-aborted-by-user-environment","errorCode":null,"errorMessage":"Publish aborted by user","messagePattern":"Publish aborted by user","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"crates/cli/src/subcommands/publish/environment.rs","lineNumber":98,"sourceCode":"/// Update configuration without inspecting or building a local module.\npub(super) async fn publish_only(\n    config: &mut crate::config::Config,\n    server: Option<&str>,\n    database: &str,\n    anonymous: bool,\n    yes: super::YesFlags,\n    input: Option<&Value>,\n    options: &super::EnvironmentOptions,\n) -> anyhow::Result<()> {\n    use crate::util::{add_auth_header_opt, get_auth_header, y_or_n};\n    use spacetimedb_client_api_messages::publish::{EnvironmentMetadata, PublishRequest, CONTENT_TYPE};\n\n    let host = config.get_host_url(server)?;\n    let server_url = reqwest::Url::parse(&host)?;\n    let hostname = server_url.host_str().context(\"Server URL has no hostname\")?;\n    if hostname != \"localhost\" && hostname != \"127.0.0.1\" {\n        println!(\"You are about to publish environment values to a non-local server: {hostname}\");\n        anyhow::ensure!(\n            y_or_n(yes.publish_to_remote, \"Are you sure you want to proceed?\")?,\n            \"Publish aborted by user\"\n        );\n    }\n    let auth = get_auth_header(config, anonymous, server, !yes.skip_login).await?;\n    let encoded = percent_encoding::percent_encode(\n        database.as_bytes(),\n        const { &percent_encoding::NON_ALPHANUMERIC.remove(b'_').remove(b'-') },\n    )\n    .to_string();\n    let url = format!(\"{host}/v1/database/{encoded}\");\n    // Neither credentials nor publish bodies may be forwarded to redirect destinations.\n    let client = reqwest::Client::builder()\n        .redirect(reqwest::redirect::Policy::none())\n        .build()?;\n    let response = add_auth_header_opt(client.get(format!(\"{url}/environment\")), &auth)\n        .send()\n        .await?;","sourceCodeStart":80,"sourceCodeEnd":116,"githubUrl":"https://github.com/clockworklabs/SpacetimeDB/blob/eddf9f5014579a50d4b67630e28b6e15cad9c4af/crates/cli/src/subcommands/publish/environment.rs#L80-L116","documentation":"`publish_only` warns when the target server's hostname is neither `localhost` nor `127.0.0.1` and asks for confirmation before sending environment values to a remote server. If the user answers \"no\" (or auto-confirm via `--yes` flags is not enabled and the prompt is declined), `ensure!` aborts with this message. This is a deliberate safety guard against leaking environment secrets to remote hosts.","triggerScenarios":"Running the environment publish flow against a remote server and typing anything other than 'y' at the \"Are you sure you want to proceed?\" prompt; running non-interactively without the auto-confirm flag (`yes.publish_to_remote`) so the prompt is declined/cancelled.","commonSituations":"CI jobs running non-interactively that hit the prompt; users who reconsider after seeing the remote-hostname warning; scripts piping input that doesn't match 'y'.","solutions":["Answer 'y' at the confirmation prompt if publishing to the remote server is intended.","Pass the auto-confirm flag for remote publishes (the option behind `yes.publish_to_remote`, e.g. `--yes`) when running non-interactively.","Publish to a local server if the values were not meant to leave the machine."],"exampleFix":"// before (CI, non-interactive)\nspacetime publish -s https://prod.example mydb   # aborts at prompt\n// after\nspacetime publish -s https://prod.example --yes mydb","handlingStrategy":"validation","validationCode":"// non-interactive runs must pass the auto-confirm flag\n[[ -t 0 ]] || set -- \"$@\" --yes   # attach --yes when stdin is not a TTY","typeGuard":null,"tryCatchPattern":"// CI: detect the abort and either add --yes or fail with context\nif output=$(spacetime publish -s \"$SERVER\" \"$DB\" 2>&1); then :; else\n  case \"$output\" in *\"Publish aborted by user\"*) echo \"Set --yes for non-interactive runs\";; esac\nfi","preventionTips":["Always pass the auto-confirm flag in CI/non-interactive contexts targeting remote servers.","Treat the remote-hostname warning as a prompt to double-check the --server URL.","Keep secrets-bearing env values on local servers unless explicitly intended for remote."],"tags":["cli","environment","user-abort","confirmation"],"backgroundTag":"operation-aborted-by-user","analyzedSha":"eddf9f5014579a50d4b67630e28b6e15cad9c4af","analyzedAt":"2026-09-20T12:15:59.611Z","contentChangedAt":"2026-09-20T12:15:59.611Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}