FixVibe

// docs / security guides / v0 checklist

v0 security checklist: 22 items for Next.js

v0 generates React + Tailwind + shadcn/ui components and full Next.js apps for Vercel. This checklist targets v0-specific risks: design iterations that re-add dangerouslySetInnerHTML, exported codebases that lose middleware, Server Actions that skip auth verification, and environment variables that have to be set again once the code lives in your own repo. 22 items across secrets, database, auth, headers, deployment, and v0-specific gotchas.

PRE = pre-deploy (audit your source). DEPLOY = at deploy time. POST = post-deploy verification.

秘密和 API 密钥(4 项)

v0 在编辑器中可以很好地处理环境变量,但导出的存储库不会继承该结构。

  1. PRE — After exporting, audit all NEXT_PUBLIC_ vars in the exported .env. 任何以 NEXT_PUBLIC_ 为前缀的内容都包含在客户端捆绑包中。确认它们是安全的(API端点,仅限匿名密钥,从不服务角色)。
  2. PRE — Verify .env.local (or .env.*.local) is in .gitignore. 当您从 v0 导出时,导出的存储库应在 .gitignore 中包含 .env*.local。验证这一点。
  3. PRE — Check that v0 didn't hardcode Stripe / Anthropic / OpenAI test keys. v0 的导出代码有时包括在组件中硬编码的sk_test_* 或pk_test_* 键。在部署到生产环境之前替换为环境变量。
  4. POST — Run Secrets in JavaScript Bundles on the deployed Vercel Preview. 如果有任何密钥到达该捆绑包,则扫描会找到它。

数据库访问控制(3项)

v0 的数据获取通常通过Next.js 服务器操作进行路由。数据库连接本身是服务器端的,但RLS策略必须是明确的。

  1. PRE — If using Supabase, enable RLS on every public table. v0 doesn't generate RLS by default. Add ENABLE ROW LEVEL SECURITY to every CREATE TABLE migration.
  2. PRE — Write explicit RLS policies per table and role. 每个策略必须通过auth.uid() 验证用户所有权。
  3. POST — Run the Supabase Row-Level Security active check on a verified domain. 检查确认RLS 执行。

身份验证和会话(4 项)

v0 支持身份验证,但不会自动强制执行服务器端验证。

  1. PRE — Ensure Server Actions use getUser(), not getSession(). 将服务器操作函数中的任何getSession() 替换为await supabase.auth.getUser()。
  2. PRE — Verify that magic-link tokens have server-enforced expiry. 默认Supabase 为 1 小时。如果 v0 生成的代码覆盖它,则恢复为默认值。
  3. PRE — Check the sign-in redirect guard. next 参数必须以/ 开头,而不能以// 开头。 v0 通常包含此内容,但请验证。
  4. POST — Test logout clears the session. 登录、注销、检查 cookie(DevTools → 应用程序 → Cookies)。必须清除会话 cookie。

HTTP 标头和CSP(3 项)

v0 导出的应用程序需要 CSP 的中间件。编辑的内部CSP不会延续。

  1. PRE — Create src/middleware.ts with CSP if it doesn't exist. v0 有时无需中间件即可导出。如果丢失,则使用基于随机数的 CSP 生成它。
  2. PRE — Verify CSP includes 'strict-dynamic' and a per-request nonce. v0 的CSP 在编辑器中是安全的,但导出的版本可能不完整。
  3. POST — Run HTTP Security Headers on a Vercel Preview. 扫描报告缺少标头和修复指南。

部署卫生(5 项)

v0 导出到您的GitHub 存储库,然后您部署到Vercel。环境设置是您的责任。

  1. DEPLOY — Verify .env.local is in .gitignore in the exported repo. 运行git ls-files .env* 进行检查。
  2. DEPLOY — Set production env vars in Vercel Settings → Environment Variables. 仅将每个范围限定为 Production。切勿与预览共享sk_live_*。
  3. DEPLOY — Audit Vercel build logs for secret echo. 检查您的构建命令中是否没有echo $SECRET 或等效命令。
  4. DEPLOY — Confirm Vercel Preview redeploys work correctly. 每个预览版部署都应生成一个新的CSP 随机数。
  5. POST — Rotate any test key that reached production. 即使sk_test_* 密钥也应该在生产曝光后轮换。

v0 特定的问题(3 项)

v0 的编辑器到存储库导出的独特模式:

  1. dangerouslySetInnerHTML can come back during design iterations. Review each exported version and replace any occurrences with sanitized alternatives (like react-markdown with remark).
  2. Exported middleware is sometimes incomplete. v0 的src/middleware.ts 导出可能缺少CSP 或HSTS。部署前验证其是否完整。
  3. Server Actions don't automatically verify auth. v0 生成没有内置身份验证检查的服务器操作。手动将 const { user } = await supabase.auth.getUser() 添加到每个状态更改服务器操作。

后续步骤

检查 general vibe coding security checklist 是否有 51 个交叉工具项。然后查看 step-by-step hardening 以了解有关 CSP、RLS 和服务器操作安全性的更深入模式。

// scan your app

别再读了,去找你应用里的漏洞。

Drop in a URL — FixVibe runs every passive check from this guide plus the rest of its 230+ passive checks, usually in under a minute. Free, no install, no card.

  • Free 层 — 每月 3 次扫描,无卡。
  • 针对任何 URL 进行被动扫描 — 无需域验证。
  • 针对 Cursor、Claude Code、Lovable、Bolt、v0、Replit 进行了调整。
  • Coding-agent prompts for code/config findings, plus operator steps for DNS/provider fixes.
v0 security checklist: 22 items for Next.js · FixVibe