FixVibe

// docs / security guides / lovable checklist

Lovable security checklist: 25 items before launch

Lovable is a fast path from idea to a published full-stack app on Supabase and Vite. This checklist targets the risks that come with that stack: RLS that must be enabled and tightened on every table Lovable creates, test keys from integrations, import.meta.env leaking env vars into the Vite bundle, GitHub sync exposing secrets, and missing security headers. 25 items across secrets, database, auth, headers, deployment, and Lovable-specific gotchas.

PRE = pre-deploy (audit your source). DEPLOY = at deploy time. POST = post-deploy verification.

秘密和 API 密钥(5 项)

如果不小心,Lovable 的市场集成和 Vite 构建可能会将环境变量泄漏到客户端包中。

  1. PRE — Audit import.meta.env references. Vite 在客户端将所有VITE_ 前缀的变量公开为import.meta.env.VITE_*。切勿使用VITE_SUPABASE_SERVICE_KEY 或VITE_STRIPE_SECRET。相反,通过仅服务器端点进行路由。
  2. PRE — Replace Lovable marketplace test keys with live restricted keys. Lovable 的 Stripe / 重新发送 / 等集成有时会附带 sk_test_* 或 pk_test_* 键。在上线之前,将它们替换为实时受限密钥,以限制泄露时造成的损害。
  3. PRE — Check the .env file is not committed. Lovable 搭建一个带有集成密钥的 .env 文件。运行git ls-files .env。如果被跟踪,请立即将其删除:git rm --cached .env 并添加到.gitignore。
  4. PRE — Verify GitHub sync doesn't expose service keys. 如果Lovable 同步到GitHub,请确认GitHub 操作工作流程或Vercel 设置不会将机密回显到构建日志中。检查您的操作 → 工作流程运行 → 单击运行 → 查看是否打印了任何机密。
  5. POST — Run Secrets in JavaScript Bundles on the deployed app. Lovable 的 Vite 版本可能会将密钥泄漏到 import.meta.env 中。被动扫描会找到它们。

数据库访问控制(5项)

Every table Lovable creates needs RLS enabled and tightened before production.

  1. PRE — Enable RLS on every public table. In Supabase Studio, Tables → for each public.* table → the RLS toggle must be ON, with policies for each command.
  2. PRE — Write explicit policies per table and role. 最小值:SELECT 允许用户仅读取 user_id = auth.uid() 所在的行。 Lovable有时会生成没有策略的表;你必须添加它们。
  3. PRE — Check Lovable's generated policies, not just the toggle. A policy such as USING (true) keeps RLS "on" while letting every caller through. Scope each policy to auth.uid(). (FORCE ROW LEVEL SECURITY only affects the table owner; it does not fix an open policy.)
  4. DEPLOY — Re-verify RLS is enforced after deploy. 部署后打开Supabase Studio。每个表的RLS 切换应该是ON。如果不是,则您的迁移不适用。
  5. POST — Run a FixVibe scan on the deployed app. Check the Supabase Row-Level Security result: it shows any table an anonymous visitor can read with your public key.

身份验证和会话(4 项)

Lovable 的身份验证是Supabase 身份验证。风险在于 Lovable 如何将其连接在一起。

  1. PRE — Ensure all API routes use getUser(), not getSession(). getSession() 读取未经验证的cookie; getUser() 使用Supabase 进行验证。在API 处理程序中搜索getSession() 并将其替换。
  2. PRE — Check Lovable's generated auth handlers for token expiry. Magic-link 令牌需要服务器强制过期。默认值为 1 小时 — 除非必要,否则不要覆盖。
  3. PRE — Audit the sign-in redirect guard. next 查询参数必须以/ 开头,而不能以// 开头。如果缺少,请手动添加守卫。
  4. POST — Test logout destroys the session. 登录、注销、检查 cookie(DevTools → 应用程序 → Cookies)。必须清除会话 cookie。

HTTP 标头和CSP(3 项)

Lovable的Vite脚手架默认不添加CSP。静态主机需要显式标头配置。

  1. PRE — Add security headers via your host's config. Vercel:vercel.json headers 数组。 Netlify:_headers 文件。包括CSP、HSTS、X-Frame-Options、X-Content-Type-Options。
  2. PRE — CSP must not have 'unsafe-inline' in script-src. 使用随机数或哈希值。 Lovable 的 Vite 构建将与严格的CSP 配合使用。
  3. POST — Run HTTP Security Headers on the deployed URL. 检查报告丢失的标头并提供特定于平台的修复指南。

部署卫生(5 项)

Lovable hosts published apps itself (Lovable docs). If you export the code and deploy it to Vercel, Netlify or Cloudflare Pages instead, each host handles headers and env vars differently.

  1. DEPLOY — Scope env vars to Production only. Vercel:设置→环境变量→范围为Production。切勿与预览共享测试 Stripe 密钥。
  2. DEPLOY — Verify build logs don't echo secrets. 检查部署提供商的构建日志。如果任何秘密被打印出来,它就会被泄露。
  3. DEPLOY — Add security headers to vercel.json or _headers. 对于Vercel,使用headers 配置。对于 Netlify / Cloudflare,请使用公共目录中的 _headers 文件。
  4. POST — Test a Vercel Preview link in a private browser window. 确保每个请求中的 CSP 随机数都是最新的并且标头存在。
  5. POST — Rotate any test key that ever shipped to production. 即使它是 sk_test_* 密钥,在您在生产中看到它后也要旋转它。

Lovable特定陷阱(3 项)

Lovable 的脚手架和部署流程独有的模式:

  1. import.meta.env is Vite-specific and all-or-nothing. Vite 通过设计在客户端包中公开 VITE_* 变量。 Vite 中不存在没有单独 API 边界的仅服务器环境概念。 Lovable的默认值是客户端为主;您必须为敏感操作添加API 路由。
  2. GitHub sync can auto-commit without review. 如果Lovable 同步更改回GitHub,请确认工作流程不会在未经您批准的情况下自动推送。否则,恶意更新可能会登陆 main.c 文件。
  3. Static-host headers are a different beast than middleware. Vercel、Netlify 和 Cloudflare 页面对标头的处理方式都不同。如果您切换主机,请重新检查您的标头配置是否已应用 - 如果标头不受支持,平台可能不会给您错误。

后续步骤

查看 general vibe coding security checklist 的 51 个交叉工具项目。然后,请参阅step-by-step hardening 以了解有关 CSP、RLS 和 auth 的更深入模式。

// scan your app

别再读了,去找你应用里的漏洞。

Drop in a URL — FixVibe runs every passive check from this guide plus the rest of its 230+ passive checks, usually in under a minute. Free, no install, no card.

  • Free 层 — 每月 3 次扫描,无卡。
  • 针对任何 URL 进行被动扫描 — 无需域验证。
  • 针对 Cursor、Claude Code、Lovable、Bolt、v0、Replit 进行了调整。
  • Coding-agent prompts for code/config findings, plus operator steps for DNS/provider fixes.
Lovable security checklist: 25 items before launch · FixVibe