// docs / security guides / v0 checklist
v0 security checklist: 22 items for Next.js
v0 generates React + Tailwind + shadcn/ui components and full Next.js apps for Vercel. This checklist targets v0-specific risks: design iterations that re-add dangerouslySetInnerHTML, exported codebases that lose middleware, Server Actions that skip auth verification, and environment variables that have to be set again once the code lives in your own repo. 22 items across secrets, database, auth, headers, deployment, and v0-specific gotchas.
PRE = pre-deploy (audit your source). DEPLOY = at deploy time. POST = post-deploy verification.
비밀 및 API 키(4개 항목)
v0은 편집기에서 env var를 잘 처리하지만 내보낸 저장소는 해당 구조를 상속하지 않습니다.
- PRE — After exporting, audit all
NEXT_PUBLIC_vars in the exported.env.NEXT_PUBLIC_접두사가 붙은 모든 항목은 클라이언트 번들에 포함되어 제공됩니다. 안전한지 확인하세요(API 엔드포인트, 익명 키만, 서비스 역할 없음). - PRE — Verify
.env.local(or.env.*.local) is in.gitignore. v0에서 내보낼 때 내보낸 저장소는.gitignore에.env*.local이 있어야 합니다. 이것을 확인하십시오. - PRE — Check that v0 didn't hardcode Stripe / Anthropic / OpenAI test keys. v0의 내보낸 코드에는 구성 요소에 하드코딩된
sk_test_*또는pk_test_*키가 포함되는 경우가 있습니다. 프로덕션에 배포하기 전에 환경 변수로 교체하세요. - POST — Run Secrets in JavaScript Bundles on the deployed Vercel Preview. 키가 번들에 도달하면 스캔에서 해당 키를 찾습니다.
데이터베이스 접근통제(3항목)
v0의 데이터 가져오기는 일반적으로 Next.js 서버 작업을 통해 라우팅됩니다. 데이터베이스 연결 자체는 서버 측이지만 RLS 정책은 명시적이어야 합니다.
- PRE — If using Supabase, enable RLS on every public table. v0 doesn't generate RLS by default. Add
ENABLE ROW LEVEL SECURITYto everyCREATE TABLEmigration. - PRE — Write explicit RLS policies per table and role. 각 정책은
auth.uid()을 통해 사용자 소유권을 확인해야 합니다. - POST — Run the Supabase Row-Level Security active check on a verified domain. 검사를 통해 RLS 시행이 확인됩니다.
인증 및 세션(4항목)
v0은 인증을 스캐폴드하지만 서버 측 확인을 자동으로 시행하지 않습니다.
- PRE — Ensure Server Actions use
getUser(), notgetSession(). 서버 작업 함수의getSession()을await supabase.auth.getUser()으로 바꿉니다. - PRE — Verify that magic-link tokens have server-enforced expiry. 기본값 Supabase은 1시간입니다. v0의 생성된 코드가 이를 재정의하는 경우 기본값으로 되돌립니다.
- PRE — Check the sign-in redirect guard.
next매개변수는//이 아니라/으로 시작해야 합니다. v0에는 일반적으로 이 내용이 포함되어 있지만 확인하세요. - POST — Test logout clears the session. 로그인, 로그아웃하고 쿠키를 검사합니다(DevTools → 애플리케이션 → 쿠키). 세션 쿠키를 지워야 합니다.
HTTP 헤더 및 CSP(3개 항목)
v0의 내보낸 앱에는 CSP에 대한 미들웨어가 필요합니다. 편집자의 내부 CSP은 전달되지 않습니다.
- PRE — Create
src/middleware.tswith CSP if it doesn't exist. v0은 미들웨어 없이 내보내는 경우가 있습니다. 누락된 경우 nonce 기반 CSP을 사용하여 생성하세요. - 편집기에 있는 PRE — Verify CSP includes
'strict-dynamic'and a per-request nonce. v0의 CSP은 안전하지만 내보낸 버전이 불완전할 수 있습니다. - POST — Run HTTP Security Headers on a Vercel Preview. 스캔에서 누락된 헤더가 보고되고 지침이 수정되었습니다.
배포 위생(5개 항목)
v0은 GitHub 저장소로 내보내고 Vercel에 배포합니다. 환경 설정은 귀하의 책임입니다.
- DEPLOY — Verify
.env.localis in.gitignorein the exported repo.git ls-files .env*을 실행하여 확인하세요. - DEPLOY — Set production env vars in Vercel Settings → Environment Variables. 각각의 범위는 Production으로만 지정됩니다.
sk_live_*을 미리보기와 공유하지 마세요. - DEPLOY — Audit Vercel build logs for secret echo. 빌드 명령에
echo $SECRET또는 이에 상응하는 항목이 없는지 확인하세요. - DEPLOY — Confirm Vercel Preview redeploys work correctly. 각 미리보기 배포는 새로운 CSP nonce를 생성해야 합니다.
- POST — Rotate any test key that reached production.
sk_test_*키도 프로덕션 노출 후 회전해야 합니다.
v0 관련 문제(3개 항목)
v0의 편집기에서 저장소로 내보내기에 고유한 패턴:
dangerouslySetInnerHTMLcan come back during design iterations. Review each exported version and replace any occurrences with sanitized alternatives (likereact-markdownwithremark).- Exported middleware is sometimes incomplete. v0의
src/middleware.ts내보내기에는 CSP 또는 HSTS이 부족할 수 있습니다. 배포하기 전에 완료되었는지 확인하세요. - Server Actions don't automatically verify auth. v0은 내장된 인증 확인 없이 서버 작업을 생성합니다. 상태를 변경하는 모든 서버 작업에
const { user } = await supabase.auth.getUser()을 수동으로 추가합니다.
다음 단계
51개 교차 도구 항목은 general vibe coding security checklist을 확인하세요. 그런 다음 CSP, RLS 및 서버 작업 보안에 대한 더 자세한 패턴을 보려면 step-by-step hardening을 검토하세요.
