// docs / security guides / bolt.new checklist
Bolt.new security checklist: 23 items before ship
Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.
PRE = pre-deploy (audit your source). DEPLOY = at deploy time. POST = post-deploy verification.
秘密和 API 密钥(5 项)
Bolt的WebContainer运行在浏览器中;导出到 GitHub 或 Netlify 将机密从隔离容器移动到公共存储库中。
- PRE — Never paste service-role keys into the Bolt terminal or chat. Anything you paste there is hard to take back. Keep keys in
.envor your host's environment settings instead. - PRE — Create a
.envfile, never hardcode secrets in code. Bolt 的开发容器很好地隔离了.env,但是当您导出到GitHub 时,.env必须位于.gitignore中。 - PRE — Confirm
.gitignoreexcludes.env,.env.local,.env.*.local. Bolt 通常会正确地构建它,但在导出之前进行验证。 - DEPLOY — Set secrets in Netlify Environment Variables, not in code. Netlify → 站点设置 → 构建和部署 → 环境。在那里添加您的密钥,范围为Production。
- POST — Run Secrets in JavaScript Bundles on the deployed URL. 如果密钥到达 Netlify 部署,扫描将找到它。
数据库访问控制(3项)
Bolt 通常与Supabase 或凸面支架一起使用。两者都有需要明确策略的默认开放模式。
- PRE — If using Supabase, enable RLS on every public table. Bolt's scaffold might not include
ENABLE ROW LEVEL SECURITYor policies. Add both in the migration. - PRE — Write policies that validate user ownership. 每个策略都应检查
auth.uid() = user_id或同等内容。 Bolt 生成的策略有时会忽略这一点。 - POST — Run a FixVibe scan on the deployed app. Check the Supabase Row-Level Security result: it shows any table an anonymous visitor can read with your public key.
身份验证和会话(4 项)
Bolt 生成 Express 或 Next.js auth。风险在于 cookie 配置和令牌验证。
- PRE — Ensure session cookies are
HttpOnly; Secure; SameSite=Lax. Bolt 有时会生成没有这些标志的 cookie。手动验证或添加它们。 - PRE — Check Bolt's generated auth handlers for server-side token verification. 如果使用
getSession(),则替换为经过验证的后端查找。 - PRE — Verify the sign-in redirect guard.
next参数必须以/开头,而不能以//开头。 Bolt有时会跳过这个;如果需要,请手动添加。 - POST — Test logout clears the session cookie. 登录、注销、检查 cookie。注销时必须删除会话 cookie。
HTTP 标头和CSP(3 项)
Bolt 的 Express/Next.js 支架很少包含CSP。静态主机需要显式配置。
- PRE — Add middleware for security headers if using Express. Bolt 的 Express 脚手架需要 CSP、HSTS、X-Frame-Options 的手动中间件。
- PRE — If using Next.js, ensure
src/middleware.tsexists with CSP. Bolt 可能会搭建它,但请验证 CSP 随机数逻辑是否正确。 - POST — Run HTTP Security Headers on the deployed Netlify URL. 扫描报告缺少标头。
部署卫生(5 项)
Bolt 导出到 GitHub 和 Netlify。两者都需要仔细配置。
- DEPLOY — Ensure Bolt exports include
.gitignorewith.envlisted. 验证GitHub 存储库在导出后没有.env文件。 - DEPLOY — Set Netlify env vars via Site settings, not GitHub secrets. Netlify 的环境变量静态加密; GitHub 秘密是为CI 设计的,而不是为部署设计的。
- DEPLOY — Audit the Netlify deploy log for secret echo. 如果构建日志打印任何环境变量,则表明它已被泄露。
- DEPLOY — Configure Netlify build command to not run
echo $SECRET. 检查您的package.json并为任何秘密输出构建脚本。 - POST — Verify Netlify redirect for HTTP → HTTPS exists. Bolt 应用程序应强制 HTTPS。 Netlify 可以通过设置强制执行此操作。
Bolt特定陷阱(3 项)
Bolt 的 WebContainer 到导出流程的独特模式:
- WebContainer isolation is lost on export. Bolt 的开发环境安全地隔离秘密,但是一旦导出到 GitHub,您就需要对
.gitignore和 env-var 规则负责。 - Treat the terminal and chat like a shared log. Don't paste credentials into either; put them in
.envor your host's environment settings. - Express
cors({ origin: '*' })is the default. Bolt 的 Express 脚手架通常包括宽容的 CORS。替换为cors({ origin: 'https://yourdomain.com', credentials: true })。
后续步骤
查看 general vibe coding security checklist 的 51 个交叉工具项目。请参阅step-by-step hardening 了解CSP、RLS 和身份验证模式。
