FixVibe

// docs / security guides / bolt.new checklist

Bolt.new security checklist: 23 items before ship

Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.

PRE = pre-deploy (audit your source). DEPLOY = at deploy time. POST = post-deploy verification.

秘密和 API 金鑰(5 項)

Bolt的WebContainer運行在瀏覽器中;匯出到 GitHub 或 Netlify 將機密從隔離容器移至公共儲存庫。

  1. PRE — Never paste service-role keys into the Bolt terminal or chat. Anything you paste there is hard to take back. Keep keys in .env or your host's environment settings instead.
  2. PRE — Create a .env file, never hardcode secrets in code. Bolt 的開發容器很好地隔離了.env,但是當您匯出到GitHub 時,.env 必須位於.gitignore 中。
  3. PRE — Confirm .gitignore excludes .env, .env.local, .env.*.local. Bolt 通常會正確地建立它,但在導出之前進行驗證。
  4. DEPLOY — Set secrets in Netlify Environment Variables, not in code. Netlify → 網站設定 → 建置與部署 → 環境。在那裡添加您的金鑰,範圍為Production。
  5. POST — Run Secrets in JavaScript Bundles on the deployed URL. 如果金鑰到達 Netlify 部署,掃描將找到它。

資料庫存取控制(3項)

Bolt 通常與Supabase 或凸面支架一起使用。兩者都有需要明確策略的預設開放模式。

  1. PRE — If using Supabase, enable RLS on every public table. Bolt's scaffold might not include ENABLE ROW LEVEL SECURITY or policies. Add both in the migration.
  2. PRE — Write policies that validate user ownership. 每個策略都應檢查 auth.uid() = user_id 或同等內容。 Bolt 產生的策略有時會忽略這一點。
  3. POST — Run a FixVibe scan on the deployed app. Check the Supabase Row-Level Security result: it shows any table an anonymous visitor can read with your public key.

身份驗證和會話(4 項)

Bolt 生成 Express 或 Next.js auth。風險在於 cookie 配置和令牌驗證。

  1. PRE — Ensure session cookies are HttpOnly; Secure; SameSite=Lax. Bolt 有時會產生沒有這些標誌的 cookie。手動驗證或新增它們。
  2. PRE — Check Bolt's generated auth handlers for server-side token verification. 如果使用getSession(),則替換為經過驗證的後端查找。
  3. PRE — Verify the sign-in redirect guard. next 參數必須以/ 開頭,而不能以// 開頭。 Bolt有時會跳過這個;如果需要,請手動添加。
  4. POST — Test logout clears the session cookie. 登入、登出、檢查 cookie。登出時必須刪除會話 cookie。

HTTP 標頭和CSP(3 項)

Bolt 的 Express/Next.js 支架很少包含CSP。靜態主機需要明確配置。

  1. PRE — Add middleware for security headers if using Express. Bolt 的 Express 鷹架需要 CSP、HSTS、X-Frame-Options 的手動中間件。
  2. PRE — If using Next.js, ensure src/middleware.ts exists with CSP. Bolt 可能會建立它,但請驗證 CSP 隨機數邏輯是否正確。
  3. POST — Run HTTP Security Headers on the deployed Netlify URL. 掃描報告缺少標頭。

部署衛生(5 項)

Bolt 匯出至 GitHub 和 Netlify。兩者都需要仔細配置。

  1. DEPLOY — Ensure Bolt exports include .gitignore with .env listed. 驗證GitHub 儲存庫匯出後沒有.env 檔案。
  2. DEPLOY — Set Netlify env vars via Site settings, not GitHub secrets. Netlify 的環境變數靜態加密;GitHub 機密是為 CI 設計的,而不是為部署設計的。
  3. DEPLOY — Audit the Netlify deploy log for secret echo. 如果建置日誌列印任何環境變量,則表示它已洩露。
  4. DEPLOY — Configure Netlify build command to not run echo $SECRET. 檢查您的package.json 並為任何秘密輸出建立腳本。
  5. POST — Verify Netlify redirect for HTTP → HTTPS exists. Bolt 應用程式應強制 HTTPS。 Netlify 可以透過設定強制執行此操作。

Bolt特定陷阱(3 項)

Bolt 的 WebContainer 到匯出流程的獨特模式:

  1. WebContainer isolation is lost on export. Bolt 的開發環境安全地隔離秘密,但一旦匯出到 GitHub,您就需要對 .gitignore 和 env-var 規則負責。
  2. Treat the terminal and chat like a shared log. Don't paste credentials into either; put them in .env or your host's environment settings.
  3. Express cors({ origin: '*' }) is the default. Bolt 的 Express 鷹架通常包括寬容的 CORS。替換為cors({ origin: 'https://yourdomain.com', credentials: true })。

後續步驟

查看 general vibe coding security checklist 的 51 個交叉工具項目。請參閱step-by-step hardening 了解CSP、RLS 和身份驗證模式。

// scan your app

別再讀了,去找你應用裡的漏洞。

Drop in a URL — FixVibe runs every passive check from this guide plus the rest of its 230+ passive checks, usually in under a minute. Free, no install, no card.

  • Free 層 — 每月 3 次掃描,無卡片。
  • 針對任何 URL 進行被動掃描 — 無需網域驗證。
  • 針對 Cursor、Claude Code、Lovable、Bolt、v0、Replit 進行了調整。
  • Coding-agent prompts for code/config findings, plus operator steps for DNS/provider fixes.
Bolt.new security checklist: 23 items before ship · FixVibe