FixVibe

// docs / security guides / lovable checklist

Lovable security checklist: 25 items before launch

Lovable is a fast path from idea to a published full-stack app on Supabase and Vite. This checklist targets the risks that come with that stack: RLS that must be enabled and tightened on every table Lovable creates, test keys from integrations, import.meta.env leaking env vars into the Vite bundle, GitHub sync exposing secrets, and missing security headers. 25 items across secrets, database, auth, headers, deployment, and Lovable-specific gotchas.

PRE = pre-deploy (audit your source). DEPLOY = at deploy time. POST = post-deploy verification.

秘密和 API 金鑰(5 項)

如果不小心,Lovable 的市場整合和 Vite 建置可能會將環境變數洩漏到客戶端套件中。

  1. PRE — Audit import.meta.env references. Vite 在客戶端將所有VITE_ 前綴的變數公開為import.meta.env.VITE_*。切勿使用VITE_SUPABASE_SERVICE_KEY 或VITE_STRIPE_SECRET。相反,透過僅伺服器端點進行路由。
  2. PRE — Replace Lovable marketplace test keys with live restricted keys. Lovable 的 Stripe / 重新發送 / 等整合有時會附帶 sk_test_* 或 pk_test_* 鍵。在上線之前,將它們替換為即時受限金鑰,以限制洩漏時造成的損害。
  3. PRE — Check the .env file is not committed. Lovable 建立一個有整合金鑰的 .env 檔案。運行git ls-files .env。如果被跟踪,請立即將其刪除:git rm --cached .env 並添加到.gitignore。
  4. PRE — Verify GitHub sync doesn't expose service keys. 如果Lovable 同步至GitHub,請確認GitHub 操作工作流程或Vercel 設定不會將機密回顯到建置日誌中。檢查您的操作 → 工作流程運行 → 按一下執行 → 查看是否列印了任何機密。
  5. POST — Run Secrets in JavaScript Bundles on the deployed app. Lovable 的 Vite 版本可能會將金鑰洩漏到 import.meta.env 中。被動掃描會找到它們。

資料庫存取控制(5項)

Every table Lovable creates needs RLS enabled and tightened before production.

  1. PRE — Enable RLS on every public table. In Supabase Studio, Tables → for each public.* table → the RLS toggle must be ON, with policies for each command.
  2. PRE — Write explicit policies per table and role. 最小值:SELECT 允許使用者只讀取 user_id = auth.uid() 所在的行。 Lovable有時會產生沒有策略的表;你必須添加它們。
  3. PRE — Check Lovable's generated policies, not just the toggle. A policy such as USING (true) keeps RLS "on" while letting every caller through. Scope each policy to auth.uid(). (FORCE ROW LEVEL SECURITY only affects the table owner; it does not fix an open policy.)
  4. DEPLOY — Re-verify RLS is enforced after deploy. 部署後開啟Supabase Studio。每個表格的RLS 切換應該是ON。如果不是,則您的遷移不適用。
  5. POST — Run a FixVibe scan on the deployed app. Check the Supabase Row-Level Security result: it shows any table an anonymous visitor can read with your public key.

身份驗證和會話(4 項)

Lovable 的身份驗證是Supabase 身份驗證。風險在於 Lovable 如何將其連接在一起。

  1. PRE — Ensure all API routes use getUser(), not getSession(). getSession() 讀取未經驗證的cookie; getUser() 使用 Supabase 進行驗證。在API 處理程序中搜尋getSession() 並將其替換。
  2. PRE — Check Lovable's generated auth handlers for token expiry. Magic-link 令牌需要伺服器強制過期。預設值為 1 小時 — 除非必要,否則不要覆蓋。
  3. PRE — Audit the sign-in redirect guard. next 查詢參數必須以/ 開頭,而不能以// 開頭。如果缺少,請手動新增守衛。
  4. POST — Test logout destroys the session. 登入、登出、檢查 cookie(DevTools → 應用程式 → Cookies)。必須清除會話 cookie。

HTTP 標頭和CSP(3 項)

Lovable的Vite腳手架預設不新增CSP。靜態主機需要明確標頭配置。

  1. PRE — Add security headers via your host's config. Vercel:vercel.json headers 陣列。 Netlify:_headers 文件。包括CSP、HSTS、X-Frame-Options、X-Content-Type-Options。
  2. PRE — CSP must not have 'unsafe-inline' in script-src. 使用隨機數或哈希值。 Lovable 的 Vite 建造將與嚴格的CSP 配合使用。
  3. POST — Run HTTP Security Headers on the deployed URL. 檢查報告遺失的標頭並提供特定於平臺的修復指南。

部署衛生(5 項)

Lovable hosts published apps itself (Lovable docs). If you export the code and deploy it to Vercel, Netlify or Cloudflare Pages instead, each host handles headers and env vars differently.

  1. DEPLOY — Scope env vars to Production only. Vercel:設定→環境變數→範圍為Production。切勿與預覽共用測試 Stripe 金鑰。
  2. DEPLOY — Verify build logs don't echo secrets. 檢查部署提供者的建置日誌。如果任何秘密被印出來,它就會被洩露。
  3. DEPLOY — Add security headers to vercel.json or _headers. 對於Vercel,使用headers 配置。對於 Netlify / Cloudflare,請使用公用目錄中的 _headers 檔案。
  4. POST — Test a Vercel Preview link in a private browser window. 確保每個請求中的 CSP 隨機數都是最新的並且標頭存在。
  5. POST — Rotate any test key that ever shipped to production. 即使它是 sk_test_* 金鑰,在您在生產中看到它後也要旋轉它。

Lovable特定陷阱(3 項)

Lovable 的鷹架與部署流程獨有的模式:

  1. import.meta.env is Vite-specific and all-or-nothing. Vite 透過設計在客戶端套件中公開 VITE_* 變數。 Vite 中不存在沒有單獨 API 邊界的僅伺服器環境概念。 Lovable的預設值是客戶端為主;您必須為敏感操作新增API 路由。
  2. GitHub sync can auto-commit without review. 如果Lovable 同步變更回GitHub,請確認工作流程不會在未經您批准的情況下自動推送。否則,惡意更新可能會登陸 main.c 檔案。
  3. Static-host headers are a different beast than middleware. Vercel、Netlify 和 Cloudflare 頁面對標頭的處理方式都不同。如果您切換主機,請重新檢查您的標頭配置是否已套用 - 如果標頭不受支持,平臺可能不會給您錯誤。

後續步驟

查看 general vibe coding security checklist 的 51 個交叉工具項目。然後,請參閱step-by-step hardening 以了解有關 CSP、RLS 和 auth 的更深入模式。

// scan your app

別再讀了,去找你應用裡的漏洞。

Drop in a URL — FixVibe runs every passive check from this guide plus the rest of its 230+ passive checks, usually in under a minute. Free, no install, no card.

  • Free 層 — 每月 3 次掃描,無卡片。
  • 針對任何 URL 進行被動掃描 — 無需網域驗證。
  • 針對 Cursor、Claude Code、Lovable、Bolt、v0、Replit 進行了調整。
  • Coding-agent prompts for code/config findings, plus operator steps for DNS/provider fixes.
Lovable security checklist: 25 items before launch · FixVibe