Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

database-restore:create posts to the plural /restores path; the API endpoint is singular /restore

オープン
#207 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
40/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
laravel, php
領域
api, databases

調査の方向性

CreateDatabaseRestoreRequest::resolveEndpoint() と CreateDatabaseRestoreRequestData::toRequestData() から始め、動作している POST /snapshots リクエストと restore リクエストを比較します。提供された curl コマンドと request ID を使って呼び出しを再現し、POST /api/databases/clusters/{cluster}/restores がトークン認証を受け付け、JSON を返し、リダイレクトせずに restore を作成すれば完了です。

索引モデルが issue の本文から書いたものです。

説明

Description

POST /api/databases/clusters/{cluster}/restores returns HTTP 302 redirecting to the dashboard instead of a JSON response, so database-restore:create cannot create a restore even once the client-side problems are out of the way.

This is a different failure from #183. That one was the Form.php fatal, fixed by #187 and shipped. With that fix in place the command now reaches the API, and the API redirects it:

{"error":true,"message":"Laravel Cloud sent back a response we could not read: HTTP 200 from POST
https://cloud.laravel.com/api/databases/clusters/db-…/restores.
The body started with: <!DOCTYPE html> <html lang=\"en\"> <head> …"}
The redirect is specific to this one route

Same token, same headers, same cluster, in the same session:

Request Result
GET /api/databases/clusters/{id} 200 JSON
GET /api/databases/clusters/{id}/snapshots 200 JSON
POST /api/databases/clusters/{id}/snapshots 200 JSON, snapshot created successfully
POST /api/databases/clusters/{id}/restores 302 to https://cloud.laravel.com

So this is not authentication, not the token, not the Accept/Content-Type pair, and not POST in general. POST /snapshots works with exactly the same setup that makes POST /restores redirect. It looks like the restores route is falling through to a web-session redirect rather than being handled as a token-authenticated API route.

Reproduction
curl -i -X POST "https://cloud.laravel.com/api/databases/clusters/${CLUSTER}/restores" \
  -H "Authorization: Bearer ${TOKEN}" \
  -H "Accept: application/vnd.api+json" \
  -H "Content-Type: application/vnd.api+json" \
  -d '{"name":"scratch-verify","database_snapshot_id":"'"${SNAPSHOT}"'"}'

Response:

HTTP/2 302
location: https://cloud.laravel.com
content-type: text/html; charset=utf-8
x-amzn-requestid: adc0a260-e499-4bf0-8234-fa2676dd1186
x-amzn-trace-id: Root=1-6a8d22d9-773df68f36f80dd4794da950;Parent=0021dc61b07a0ccf;Sampled=0

The payload shape matches App\Client\Requests\CreateDatabaseRestoreRequestData::toRequestData() (name, database_snapshot_id, restore_time) and the endpoint matches CreateDatabaseRestoreRequest::resolveEndpoint(), so the CLI's own request is being redirected the same way. Reproduced via curl and via the CLI itself.

No restore cluster is created, and the source cluster is unaffected.

Environment
  • laravel/cloud-cli v0.5.2, with #183 / #187 already in place
  • PHP 8.4 / macOS (darwin 25.5.0)
  • Cluster type laravel_mysql_84, region ap-southeast-2
  • Snapshot used: type: manual, status: available, created via POST /snapshots minutes earlier
Impact

Restoring a snapshot is the documented way to get a copy of a production database without exposing production itself (Laravel MySQL, "How to download a backup"): restore a snapshot to a new cluster, enable public access on the copy, dump from it, delete the copy.

With this route redirecting, that workflow cannot be scripted at all. The remaining option is enabling the public endpoint on the production cluster and dumping from that, which is exactly what the documented workflow exists to avoid. We are verifying that backups are restorable, and creating snapshots works while restoring them does not, so the half that actually matters cannot be exercised.

Request

Could you confirm whether POST /api/databases/clusters/{cluster}/restores is expected to accept API-token auth, and if so route it as an API endpoint rather than redirecting? Request ID adc0a260-e499-4bf0-8234-fa2676dd1186 should identify the call in your logs.

主要言語
PHP
スター
47
フォーク
11
平均マージ
5時間 46分
マージ済み PR(30日)
12

環境構築

このプロジェクトの環境構築ファイルはまだ確認していません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

laravel/cloud-cli のほかの issue

laravel/cloud-cli の issue をすべて見る

似ている issue

PHP の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。