FixVibe

// docs / security guides / bolt.new checklist

Bolt.new security checklist: 23 items before ship

Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.

PRE = pre-deploy (audit your source). DEPLOY = at deploy time. POST = post-deploy verification.

Rahasia dan kunci API (5 item)

WebContainer Bolt berjalan di browser; mengekspor ke GitHub atau Netlify memindahkan rahasia dari wadah terisolasi ke repo publik.

  1. PRE β€” Never paste service-role keys into the Bolt terminal or chat. Anything you paste there is hard to take back. Keep keys in .env or your host's environment settings instead.
  2. PRE β€” Create a .env file, never hardcode secrets in code. Bolt wadah pengembang mengisolasi .env dengan baik, namun ketika Anda mengekspor ke GitHub, .env harus dalam .gitignore.
  3. PRE β€” Confirm .gitignore excludes .env, .env.local, .env.*.local. Bolt biasanya melakukan scaffolding dengan benar, tetapi verifikasi sebelum mengekspor.
  4. DEPLOY β€” Set secrets in Netlify Environment Variables, not in code. Netlify β†’ Pengaturan situs β†’ Bangun & terapkan β†’ Lingkungan. Tambahkan kunci Anda di sana, dengan cakupan Production.
  5. POST β€” Run Secrets in JavaScript Bundles on the deployed URL. Jika kunci mencapai penerapan Netlify, pemindaian akan menemukannya.

Kontrol akses basis data (3 item)

Bolt biasanya scaffold dengan Supabase atau Convex. Keduanya memiliki mode terbuka default yang memerlukan kebijakan eksplisit.

  1. PRE β€” If using Supabase, enable RLS on every public table. Bolt's scaffold might not include ENABLE ROW LEVEL SECURITY or policies. Add both in the migration.
  2. PRE β€” Write policies that validate user ownership. Setiap kebijakan harus memeriksa auth.uid() = user_id atau setara. Kebijakan yang dihasilkan Bolt terkadang melewatkan hal ini.
  3. POST β€” Run a FixVibe scan on the deployed app. Check the Supabase Row-Level Security result: it shows any table an anonymous visitor can read with your public key.

Otentikasi dan sesi (4 item)

Bolt menghasilkan Express atau Next.js auth. Risikonya ada pada konfigurasi cookie dan validasi token.

  1. PRE β€” Ensure session cookies are HttpOnly; Secure; SameSite=Lax. Bolt terkadang menghasilkan cookie tanpa tanda ini. Verifikasi atau tambahkan secara manual.
  2. PRE β€” Check Bolt's generated auth handlers for server-side token verification. Jika getSession() digunakan, ganti dengan pencarian backend terverifikasi.
  3. PRE β€” Verify the sign-in redirect guard. Param next harus dimulai dengan /, jangan pernah //. Bolt terkadang melewatkan ini; tambahkan secara manual jika diperlukan.
  4. POST β€” Test logout clears the session cookie. Masuk, keluar, periksa cookie. Cookie sesi harus dihapus saat logout.

HTTP header dan CSP (3 item)

Perancah Bolt Express/Next.js jarang menyertakan CSP. Host statis memerlukan konfigurasi eksplisit.

  1. PRE β€” Add middleware for security headers if using Express. Bolt Perancah Ekspres memerlukan middleware manual untuk CSP, HSTS, X-Frame-Options.
  2. PRE β€” If using Next.js, ensure src/middleware.ts exists with CSP. Bolt mungkin melakukan scaffold, tetapi pastikan logika nonce CSP sudah benar.
  3. POST β€” Run HTTP Security Headers on the deployed Netlify URL. Pemindaian melaporkan header yang hilang.

Kebersihan penempatan (5 item)

Bolt ekspor ke GitHub dan Netlify. Keduanya memerlukan konfigurasi yang cermat.

  1. DEPLOY β€” Ensure Bolt exports include .gitignore with .env listed. Verifikasi bahwa repo GitHub tidak memiliki file .env setelah diekspor.
  2. DEPLOY β€” Set Netlify env vars via Site settings, not GitHub secrets. Variabel Lingkungan Netlify dienkripsi saat tidak digunakan; GitHub rahasia dirancang untuk CI, bukan penerapan.
  3. DEPLOY β€” Audit the Netlify deploy log for secret echo. Jika log build mencetak env var apa pun, maka log tersebut disusupi.
  4. DEPLOY β€” Configure Netlify build command to not run echo $SECRET. Periksa package.json Anda dan buat skrip untuk keluaran rahasia apa pun.
  5. POST β€” Verify Netlify redirect for HTTP β†’ HTTPS exists. Bolt aplikasi harus memaksa HTTPS. Netlify dapat menerapkan ini melalui pengaturan.

Bolt - gotcha khusus (3 item)

Pola unik untuk alur WebContainer-to-ekspor Bolt:

  1. Lingkungan pengembang WebContainer isolation is lost on export. Bolt mengisolasi rahasia dengan aman, namun begitu Anda mengekspor ke GitHub, Anda bertanggung jawab atas .gitignore dan disiplin env-var.
  2. Treat the terminal and chat like a shared log. Don't paste credentials into either; put them in .env or your host's environment settings.
  3. Express cors({ origin: '*' }) is the default. Bolt Perancah Ekspres sering kali menyertakan CORS yang permisif. Ganti dengan cors({ origin: 'https://yourdomain.com', credentials: true }).

Langkah selanjutnya

Tinjau general vibe coding security checklist untuk 51 item lintas alat. Lihat step-by-step hardening untuk CSP, RLS, dan pola autentikasi.

// scan your app

Cukup membaca. Saatnya temukan celah di aplikasimu.

Drop in a URL β€” FixVibe runs every passive check from this guide plus the rest of its 230+ passive checks, usually in under a minute. Free, no install, no card.

  • Free tingkat β€” 3 pemindaian / bulan, tanpa kartu.
  • Pemindaian pasif terhadap URL apa pun β€” tidak memerlukan verifikasi domain.
  • Disetel untuk Cursor, Claude Code, Lovable, Bolt, v0, Replit.
  • Coding-agent prompts for code/config findings, plus operator steps for DNS/provider fixes.
Bolt.new security checklist: 23 items before ship Β· FixVibe