FixVibe

// docs / security guides / lovable checklist

Lovable security checklist: 25 items before launch

Lovable is a fast path from idea to a published full-stack app on Supabase and Vite. This checklist targets the risks that come with that stack: RLS that must be enabled and tightened on every table Lovable creates, test keys from integrations, import.meta.env leaking env vars into the Vite bundle, GitHub sync exposing secrets, and missing security headers. 25 items across secrets, database, auth, headers, deployment, and Lovable-specific gotchas.

PRE = pre-deploy (audit your source). DEPLOY = at deploy time. POST = post-deploy verification.

비밀 및 API 키(5개 항목)

Lovable의 마켓플레이스 통합과 Vite 빌드는 주의하지 않으면 환경 변수를 클라이언트 번들로 유출할 수 있습니다.

  1. PRE — Audit import.meta.env references. Vite는 클라이언트에서 VITE_ 접두사가 붙은 모든 변수를 import.meta.env.VITE_*으로 노출합니다. VITE_SUPABASE_SERVICE_KEY 또는 VITE_STRIPE_SECRET을 사용하지 마세요. 대신 서버 전용 엔드포인트를 통해 라우팅하세요.
  2. PRE — Replace Lovable marketplace test keys with live restricted keys. Lovable의 Stripe / 재전송 / 등의 통합은 때때로 sk_test_* 또는 pk_test_* 키와 함께 제공됩니다. 라이브로 시작하기 전에 손상된 경우 손상을 제한하는 라이브 제한 키로 교환하세요.
  3. PRE — Check the .env file is not committed. Lovable은 통합 키를 사용하여 .env 파일을 스캐폴드합니다. git ls-files .env을 실행합니다. 추적되는 경우 즉시 제거하세요: git rm --cached .env 그리고 .gitignore에 추가하세요.
  4. PRE — Verify GitHub sync doesn't expose service keys. Lovable이 GitHub으로 동기화되는 경우 GitHub 작업 워크플로를 확인하거나 Vercel 설정이 빌드 로그에 비밀을 반영하지 않는지 확인하세요. 작업 확인 → 워크플로 실행 → 실행 클릭 → 비밀이 인쇄되는지 확인하세요.
  5. POST — Run Secrets in JavaScript Bundles on the deployed app. Lovable의 Vite 빌드는 키를 import.meta.env으로 유출할 수 있습니다. 패시브 스캔으로 찾을 수 있습니다.

데이터베이스 접근통제(5항목)

Every table Lovable creates needs RLS enabled and tightened before production.

  1. PRE — Enable RLS on every public table. In Supabase Studio, Tables → for each public.* table → the RLS toggle must be ON, with policies for each command.
  2. PRE — Write explicit policies per table and role. 최소: SELECT은 사용자가 user_id = auth.uid()인 행만 읽을 수 있도록 허용합니다. Lovable은 때때로 정책 없이 테이블을 생성합니다. 이를 추가해야 합니다.
  3. PRE — Check Lovable's generated policies, not just the toggle. A policy such as USING (true) keeps RLS "on" while letting every caller through. Scope each policy to auth.uid(). (FORCE ROW LEVEL SECURITY only affects the table owner; it does not fix an open policy.)
  4. DEPLOY — Re-verify RLS is enforced after deploy. 배포 후 Supabase Studio를 엽니다. 각 테이블의 RLS 토글은 ON이어야 합니다. 그렇지 않은 경우 마이그레이션이 적용되지 않은 것입니다.
  5. POST — Run a FixVibe scan on the deployed app. Check the Supabase Row-Level Security result: it shows any table an anonymous visitor can read with your public key.

인증 및 세션(4항목)

Lovable의 인증은 Supabase 인증입니다. 위험은 Lovable을 어떻게 연결하느냐에 있습니다.

  1. PRE — Ensure all API routes use getUser(), not getSession(). getSession() 확인되지 않은 쿠키를 읽습니다. getUser()은 Supabase으로 유효성을 검사합니다. API 처리기에서 getSession()을 검색하여 바꿉니다.
  2. PRE — Check Lovable's generated auth handlers for token expiry. 매직링크 토큰은 서버 강제 만료가 필요합니다. 기본값은 1시간입니다. 꼭 필요한 경우가 아니면 재정의하지 마세요.
  3. PRE — Audit the sign-in redirect guard. next 쿼리 매개변수는 //이 아니라 /으로 시작해야 합니다. 누락된 경우 가드를 수동으로 추가하세요.
  4. POST — Test logout destroys the session. 로그인, 로그아웃하고 쿠키를 검사합니다(DevTools → 애플리케이션 → 쿠키). 세션 쿠키를 지워야 합니다.

HTTP 헤더 및 CSP(3개 항목)

Lovable의 Vite 스캐폴드는 기본적으로 CSP을 추가하지 않습니다. 정적 호스트에는 명시적인 헤더 구성이 필요합니다.

  1. PRE — Add security headers via your host's config. Vercel: vercel.json headers 배열. 넷티파이: _headers 파일. CSP, HSTS, X-Frame-Options, X-Content-Type-Options를 포함합니다.
  2. PRE — CSP must not have 'unsafe-inline' in script-src. nonce 또는 해시를 사용하세요. Lovable의 Vite 빌드는 엄격한 CSP에서 작동합니다.
  3. POST — Run HTTP Security Headers on the deployed URL. 검사에서는 누락된 헤더를 보고하고 플랫폼별 수정 지침을 제공합니다.

배포 위생(5개 항목)

Lovable hosts published apps itself (Lovable docs). If you export the code and deploy it to Vercel, Netlify or Cloudflare Pages instead, each host handles headers and env vars differently.

  1. DEPLOY — Scope env vars to Production only. Vercel: 설정 → 환경 변수 → 각각 Production으로 범위를 지정합니다. 테스트 Stripe 키를 미리보기와 공유하지 마세요.
  2. DEPLOY — Verify build logs don't echo secrets. 배포 공급자의 빌드 로그를 확인하세요. 비밀이 인쇄되면 보안이 침해된 것입니다.
  3. DEPLOY — Add security headers to vercel.json or _headers. Vercel의 경우 headers 구성을 사용합니다. Netlify / Cloudflare의 경우 공개 디렉토리의 _headers 파일을 사용하세요.
  4. POST — Test a Vercel Preview link in a private browser window. 각 요청에서 CSP nonce가 최신이고 헤더가 있는지 확인하세요.
  5. POST — Rotate any test key that ever shipped to production. sk_test_* 키이더라도 프로덕션에서 본 후에 회전시켜 보세요.

Lovable 관련 문제(3개 항목)

Lovable의 스캐폴드 및 배포 흐름에 고유한 패턴:

  1. import.meta.env is Vite-specific and all-or-nothing. Vite는 설계상 클라이언트 번들에 VITE_* 변수를 노출합니다. Vite에는 별도의 API 경계가 없는 서버 전용 환경 개념이 없습니다. Lovable의 기본값은 클라이언트 중심입니다. 민감한 작업을 위해서는 API 경로를 추가해야 합니다.
  2. GitHub sync can auto-commit without review. Lovable이 변경 사항을 GitHub으로 다시 동기화하는 경우 워크플로가 승인 없이 자동 푸시되지 않는지 확인하세요. 그렇지 않으면 악성 업데이트가 기본으로 실행될 수 있습니다.
  3. Static-host headers are a different beast than middleware. Vercel, Netlify 및 Cloudflare 페이지는 모두 헤더를 다르게 처리합니다. 호스트를 전환하는 경우 헤더 구성이 적용되었는지 다시 확인하세요. 헤더가 지원되지 않으면 플랫폼에서 오류가 발생하지 않을 수 있습니다.

다음 단계

51개 교차 도구 항목에 대해서는 general vibe coding security checklist을 검토하세요. 그런 다음 CSP, RLS 및 인증에 대한 더 자세한 패턴을 보려면 step-by-step hardening을 참조하세요.

// scan your app

그만 읽고, 당신 앱의 취약점을 직접 찾아보세요.

Drop in a URL — FixVibe runs every passive check from this guide plus the rest of its 230+ passive checks, usually in under a minute. Free, no install, no card.

  • Free 계층 — 월 3회 스캔, 카드 없음.
  • URL에 대한 수동 검색 — 도메인 확인이 필요하지 않습니다.
  • Cursor, Claude Code, Lovable, Bolt, v0, Replit에 맞춰 조정되었습니다.
  • Coding-agent prompts for code/config findings, plus operator steps for DNS/provider fixes.
무료 스캔 실행 →

가입 불필요

Lovable security checklist: 25 items before launch · FixVibe