FixVibe

// docs / security guides / bolt.new checklist

Bolt.new security checklist: 23 items before ship

Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.

PRE = pre-deploy (audit your source). DEPLOY = at deploy time. POST = post-deploy verification.

الأسرار ومفاتيح API (5 عناصر)

يتم تشغيل WebContainer Bolt في المستعرض؛ يقوم التصدير إلى GitHub أو Netlify بنقل الأسرار من الحاوية المعزولة إلى الريبو العام.

  1. PRE — Never paste service-role keys into the Bolt terminal or chat. Anything you paste there is hard to take back. Keep keys in .env or your host's environment settings instead.
  2. PRE — Create a .env file, never hardcode secrets in code. Bolt تعزل حاوية التطوير .env بشكل جيد، ولكن عند التصدير إلى GitHub، يجب أن يكون .env في .gitignore.
  3. PRE — Confirm .gitignore excludes .env, .env.local, .env.*.local. Bolt عادةً ما يدعم ذلك بشكل صحيح، ولكن تحقق منه قبل التصدير.
  4. DEPLOY — Set secrets in Netlify Environment Variables, not in code. Netlify → إعدادات الموقع → البناء والنشر → البيئة. أضف مفاتيحك هناك، ضمن نطاق Production.
  5. POST — Run Secrets in JavaScript Bundles on the deployed URL. إذا وصل المفتاح إلى نشر Netlify، فسوف يعثر عليه الفحص.

التحكم في الوصول إلى قاعدة البيانات (3 عناصر)

Bolt عادةً ما تكون السقالات ذات Supabase أو محدبة. كلاهما لهما أوضاع مفتوحة افتراضيًا تحتاج إلى سياسات واضحة.

  1. PRE — If using Supabase, enable RLS on every public table. Bolt's scaffold might not include ENABLE ROW LEVEL SECURITY or policies. Add both in the migration.
  2. PRE — Write policies that validate user ownership. يجب على كل سياسة التحقق من auth.uid() = user_id أو ما يعادله. سياسات Bolt التي تم إنشاؤها تفتقد هذا أحيانًا.
  3. POST — Run a FixVibe scan on the deployed app. Check the Supabase Row-Level Security result: it shows any table an anonymous visitor can read with your public key.

المصادقة والجلسات (4 عناصر)

Bolt يُنشئ مصادقة Express أو Next.js. تكمن المخاطرة في تكوين ملفات تعريف الارتباط والتحقق من صحة الرمز المميز.

  1. PRE — Ensure session cookies are HttpOnly; Secure; SameSite=Lax. Bolt يقوم أحيانًا بإنشاء ملفات تعريف الارتباط بدون هذه العلامات. قم بالتحقق منها أو إضافتها يدويًا.
  2. PRE — Check Bolt's generated auth handlers for server-side token verification. إذا تم استخدام getSession()، فاستبدله بالبحث الخلفي الذي تم التحقق منه.
  3. PRE — Verify the sign-in redirect guard. يجب أن تبدأ المعلمة next بـ /، وليس // أبدًا. Bolt يتخطى هذا أحيانًا؛ قم بإضافته يدويًا إذا لزم الأمر.
  4. POST — Test logout clears the session cookie. قم بتسجيل الدخول، وتسجيل الخروج، وفحص ملفات تعريف الارتباط. يجب حذف ملف تعريف الارتباط للجلسة عند تسجيل الخروج.

HTTP الرؤوس وCSP (3 عناصر)

نادرًا ما تشتمل سقالات Bolt Express/Next.js على CSP. يحتاج المضيفون الثابتون إلى تكوين واضح.

  1. تحتاج سقالة Express PRE — Add middleware for security headers if using Express. Bolt إلى برامج وسيطة يدوية لـ CSP وHSTS وخيارات الإطار X.
  2. PRE — If using Next.js, ensure src/middleware.ts exists with CSP. Bolt قد يدعمها، لكن تأكد من صحة المنطق CSP.
  3. POST — Run HTTP Security Headers on the deployed Netlify URL. يُبلغ الفحص عن رؤوس مفقودة.

نظافة النشر (5 عناصر)

Bolt يتم التصدير إلى GitHub وNetlify. كلاهما يحتاج إلى تكوين دقيق.

  1. DEPLOY — Ensure Bolt exports include .gitignore with .env listed. تحقق من أن GitHub الريبو لا يحتوي على ملفات .env بعد التصدير.
  2. DEPLOY — Set Netlify env vars via Site settings, not GitHub secrets. يتم تشفير متغيرات بيئة Netlify في حالة عدم النشاط؛ GitHub الأسرار مصممة لـ CI، وليس للنشر.
  3. DEPLOY — Audit the Netlify deploy log for secret echo. إذا قام سجل البناء بطباعة أي env var، فهذا يعني أنه تم اختراقه.
  4. DEPLOY — Configure Netlify build command to not run echo $SECRET. تحقق من package.json وقم بإنشاء نصوص برمجية لأي مخرجات سرية.
  5. POST — Verify Netlify redirect for HTTP → HTTPS exists. Bolt يجب أن تفرض التطبيقات HTTPS. يمكن لـ Netlify فرض ذلك عبر الإعدادات.

Bolt- مشكلات محددة (3 عناصر)

الأنماط الفريدة لتدفق WebContainer-to-export الخاص بـ Bolt:

  1. تعمل بيئة التطوير WebContainer isolation is lost on export. Bolt على عزل الأسرار بشكل آمن، ولكن بمجرد التصدير إلى GitHub، تصبح مسؤولاً عن .gitignore ونظام env-var.
  2. Treat the terminal and chat like a shared log. Don't paste credentials into either; put them in .env or your host's environment settings.
  3. Express cors({ origin: '*' }) is the default. Bolt تتضمن سقالة Express غالبًا CORS متساهلة. استبدل بـ cors({ origin: 'https://yourdomain.com', credentials: true }).

الخطوات التالية

قم بمراجعة general vibe coding security checklist للحصول على 51 عنصرًا متعدد الأدوات. راجع step-by-step hardening لمعرفة CSP وRLS وأنماط المصادقة.

// scan your app

كفّ عن القراءة. ابدأ بإيجاد الثغرات في تطبيقك.

Drop in a URL — FixVibe runs every passive check from this guide plus the rest of its 230+ passive checks, usually in under a minute. Free, no install, no card.

  • Free الطبقة — 3 عمليات مسح/شهر، بدون بطاقة.
  • عمليات الفحص السلبي ضد أي URL — لا حاجة للتحقق من المجال.
  • تم ضبطه على Cursor، Claude Code، Lovable، Bolt، v0، Replit.
  • Coding-agent prompts for code/config findings, plus operator steps for DNS/provider fixes.
Bolt.new security checklist: 23 items before ship · FixVibe