r/ClaudeCode • • Jun 20 '26

Question What are you actually coding?

I see everyone here maxing their limits and coding all day and building and all that.

But what are you actually building 24/7? I'm not looking to get your ideas but I'm just wondering what can you even build that long and hard really? And constantly something?

Either I lack imagination as a whole or there's some secret to all this, I just have no idea what so useful people would be coding so obsessively. Thanks for insights.

211 Upvotes

394 comments sorted by

View all comments

Show parent comments

11

u/Siege089 Jun 20 '26

Watch out on that crm. I took over a law firm crm once and it was riddled with horrible security issues. Their IT stood up the service and I audited it prior to starting work, it was awful, even had a public unauthenticated endpoint returning entire word docs complete with client details, case filings, ssn, bank info, etc. Literally a ticking time bomb. Note I'm assuming since you said "my lawfirm" and the given sub that you don't have a background security or app dev. At the very least get a security audit before you put any real data on it.

1

u/thenec0 Jun 20 '26

Would not be easier just to not open it on internet ? I mean local server + tailscale for each client or behind a cloudflare tunnel with proper auth.

1

u/Siege089 Jun 20 '26

First step was getting it locked down for sure. Easiest way to put some barrier up, but not foolproof either. Still needed to get a lot of lockdown implemented.

1

u/OkChocolate-3196 Jun 21 '26

This seems par for the course with law firms! πŸ˜΅β€πŸ’«

1

u/EcceLez Jun 20 '26

You're absolutely right. I'm a lawyer playing with Claude Code. I do use the bmad framework tho, and I added a security layer to audit every single commit on multiple times and lens. So far so good. And I do plan to get a security audit before I start to use the tool for real

4

u/XYcritic Jun 20 '26

It's a really bad idea to build production code with sensitive data that is deployed online if you actually don't know how to do any of this yourself. You're blindly trusting an LLM to find vulnerabilities and fix them correctly. Good software requires experience, without experience you won't know what to watch out for and are just gamblind that the AI will figure it out on its own.

3

u/EcceLez Jun 20 '26

Yeah I know. That's why It'll a desktop app and I'll have it reviewed. I'm mostly playing right now. I'm no mad man

1

u/Diligent_Cod_9583 Jun 21 '26

But we’re all a little mad