// docs / security guides / bolt.new checklist
Bolt.new security checklist: 23 items before ship
Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.
PRE = pre-deploy (audit your source). DEPLOY = at deploy time. POST = post-deploy verification.
비밀 및 API 키(5개 항목)
Bolt의 WebContainer는 브라우저에서 실행됩니다. GitHub 또는 Netlify로 내보내면 비밀이 격리된 컨테이너에서 공개 저장소로 이동됩니다.
- PRE — Never paste service-role keys into the Bolt terminal or chat. Anything you paste there is hard to take back. Keep keys in
.envor your host's environment settings instead. - PRE — Create a
.envfile, never hardcode secrets in code. Bolt의 개발 컨테이너는.env을 훌륭하게 분리하지만 GitHub으로 내보낼 때.env은.gitignore에 있어야 합니다. - PRE — Confirm
.gitignoreexcludes.env,.env.local,.env.*.local. Bolt은 일반적으로 이를 올바르게 스캐폴드하지만 내보내기 전에 확인하십시오. - DEPLOY — Set secrets in Netlify Environment Variables, not in code. Netlify → 사이트 설정 → 빌드 및 배포 → 환경. Production 범위의 키를 여기에 추가하세요.
- POST — Run Secrets in JavaScript Bundles on the deployed URL. 키가 Netlify 배포에 도달하면 스캔에서 해당 키를 찾습니다.
데이터베이스 접근통제(3항목)
Bolt은 일반적으로 Supabase 또는 Convex를 사용한 스캐폴드입니다. 둘 다 명시적인 정책이 필요한 기본 개방 모드를 가지고 있습니다.
- PRE — If using Supabase, enable RLS on every public table. Bolt's scaffold might not include
ENABLE ROW LEVEL SECURITYor policies. Add both in the migration. - PRE — Write policies that validate user ownership. 모든 정책은
auth.uid() = user_id또는 이에 상응하는 항목을 확인해야 합니다. Bolt의 생성된 정책에서 이를 놓치는 경우가 있습니다. - POST — Run a FixVibe scan on the deployed app. Check the Supabase Row-Level Security result: it shows any table an anonymous visitor can read with your public key.
인증 및 세션(4항목)
Bolt은 Express 또는 Next.js 인증을 생성합니다. 위험은 쿠키 구성 및 토큰 유효성 검사에 있습니다.
- PRE — Ensure session cookies are
HttpOnly; Secure; SameSite=Lax. Bolt은 때때로 이러한 플래그 없이 쿠키를 생성합니다. 수동으로 확인하거나 추가하세요. - PRE — Check Bolt's generated auth handlers for server-side token verification.
getSession()을 사용하는 경우 검증된 백엔드 조회로 대체합니다. - PRE — Verify the sign-in redirect guard.
next매개변수는//이 아니라/으로 시작해야 합니다. Bolt는 때때로 이것을 건너뜁니다. 필요한 경우 수동으로 추가하세요. - POST — Test logout clears the session cookie. 로그인하고 로그아웃하고 쿠키를 검사하세요. 세션 쿠키는 로그아웃 시 삭제되어야 합니다.
HTTP 헤더 및 CSP(3개 항목)
Bolt의 Express/Next.js 스캐폴드에는 CSP이 포함되는 경우가 거의 없습니다. 정적 호스트에는 명시적인 구성이 필요합니다.
- PRE — Add middleware for security headers if using Express. Bolt의 Express 스캐폴드에는 CSP, HSTS, X-Frame-Options에 대한 수동 미들웨어가 필요합니다.
- PRE — If using Next.js, ensure
src/middleware.tsexists with CSP. Bolt은 이를 발판으로 삼을 수 있지만 CSP nonce 논리가 올바른지 확인하세요. - POST — Run HTTP Security Headers on the deployed Netlify URL. 스캔에서 헤더가 누락되었다고 보고합니다.
배포 위생(5개 항목)
Bolt은 GitHub 및 Netlify로 내보냅니다. 둘 다 신중한 구성이 필요합니다.
- DEPLOY — Ensure Bolt exports include
.gitignorewith.envlisted. 내보낸 후 GitHub 저장소에.env파일이 없는지 확인하세요. - DEPLOY — Set Netlify env vars via Site settings, not GitHub secrets. Netlify의 환경 변수는 저장 시 암호화됩니다. GitHub 비밀은 배포가 아닌 CI용으로 설계되었습니다.
- DEPLOY — Audit the Netlify deploy log for secret echo. 빌드 로그에 env var가 인쇄되면 손상된 것입니다.
- DEPLOY — Configure Netlify build command to not run
echo $SECRET.package.json을 확인하고 비밀 출력에 대한 스크립트를 작성하세요. - POST — Verify Netlify redirect for HTTP → HTTPS exists. Bolt 앱은 HTTPS을 강제해야 합니다. Netlify는 설정을 통해 이를 시행할 수 있습니다.
Bolt 관련 문제(3개 항목)
Bolt의 WebContainer-to-export 흐름에 고유한 패턴:
- WebContainer isolation is lost on export. Bolt의 개발 환경은 비밀을 안전하게 격리하지만 GitHub으로 내보낸 후에는
.gitignore및 env-var 규율에 대한 책임이 있습니다. - Treat the terminal and chat like a shared log. Don't paste credentials into either; put them in
.envor your host's environment settings. - Express
cors({ origin: '*' })is the default. Bolt의 Express 스캐폴드에는 허용되는 CORS이 포함되는 경우가 많습니다.cors({ origin: 'https://yourdomain.com', credentials: true })으로 바꿉니다.
다음 단계
51개 교차 도구 항목에 대해서는 general vibe coding security checklist을 검토하세요. CSP, RLS 및 인증 패턴은 step-by-step hardening을 참조하세요.
