// docs / security guides / v0 checklist
v0 security checklist: 22 items for Next.js
v0 generates React + Tailwind + shadcn/ui components and full Next.js apps for Vercel. This checklist targets v0-specific risks: design iterations that re-add dangerouslySetInnerHTML, exported codebases that lose middleware, Server Actions that skip auth verification, and environment variables that have to be set again once the code lives in your own repo. 22 items across secrets, database, auth, headers, deployment, and v0-specific gotchas.
PRE = pre-deploy (audit your source). DEPLOY = at deploy time. POST = post-deploy verification.
秘密和 API 金鑰(4 項)
v0 在編輯器中可以很好地處理環境變量,但導出的儲存庫不會繼承該結構。
- PRE — After exporting, audit all
NEXT_PUBLIC_vars in the exported.env. 任何以NEXT_PUBLIC_為前綴的內容都包含在客戶端捆綁包中。確認它們是安全的(API端點,僅限匿名金鑰,從不服務角色)。 - PRE — Verify
.env.local(or.env.*.local) is in.gitignore. 當您從 v0 匯出時,匯出的儲存庫應在.gitignore中包含.env*.local。驗證這一點。 - PRE — Check that v0 didn't hardcode Stripe / Anthropic / OpenAI test keys. v0 的匯出程式碼有時會包含在元件中硬編碼的
sk_test_*或pk_test_*鍵。在部署到生產環境之前替換為環境變數。 - POST — Run Secrets in JavaScript Bundles on the deployed Vercel Preview. 如果有任何金鑰到達該捆綁包,則掃描會找到它。
資料庫存取控制(3項)
v0 的資料取得通常透過Next.js 伺服器操作進行路由。資料庫連線本身是伺服器端的,但RLS策略必須是明確的。
- PRE — If using Supabase, enable RLS on every public table. v0 doesn't generate RLS by default. Add
ENABLE ROW LEVEL SECURITYto everyCREATE TABLEmigration. - PRE — Write explicit RLS policies per table and role. 每個策略必須透過
auth.uid()驗證使用者所有權。 - POST — Run the Supabase Row-Level Security active check on a verified domain. 檢查確認RLS 執行。
身份驗證和會話(4 項)
v0 支援身份驗證,但不會自動強制執行伺服器端驗證。
- PRE — Ensure Server Actions use
getUser(), notgetSession(). 將伺服器操作函數中的任何getSession()替換為await supabase.auth.getUser()。 - PRE — Verify that magic-link tokens have server-enforced expiry. 預設Supabase 為 1 小時。如果 v0 產生的程式碼覆蓋它,則恢復為預設值。
- PRE — Check the sign-in redirect guard.
next參數必須以/開頭,而不能以//開頭。 v0 通常包含此內容,但請驗證。 - POST — Test logout clears the session. 登入、登出、檢查 cookie(DevTools → 應用程式 → Cookies)。必須清除會話 cookie。
HTTP 標頭和CSP(3 項)
v0 匯出的應用程式需要 CSP 的中間件。編輯的內部CSP不會延續。
- PRE — Create
src/middleware.tswith CSP if it doesn't exist. v0 有時無需中間件即可匯出。如果遺失,則使用基於隨機數的 CSP 來產生它。 - PRE — Verify CSP includes
'strict-dynamic'and a per-request nonce. v0 的CSP 在編輯器中是安全的,但導出的版本可能不完整。 - POST — Run HTTP Security Headers on a Vercel Preview. 掃描報告缺少標頭和修復指南。
部署衛生(5 項)
v0 匯出到您的GitHub 儲存庫,然後您部署到Vercel。環境設定是您的責任。
- DEPLOY — Verify
.env.localis in.gitignorein the exported repo. 運行git ls-files .env*進行檢查。 - DEPLOY — Set production env vars in Vercel Settings → Environment Variables. 僅將每個範圍限定為 Production。切勿與預覽分享
sk_live_*。 - DEPLOY — Audit Vercel build logs for secret echo. 檢查您的建置指令中是否沒有
echo $SECRET或等效指令。 - DEPLOY — Confirm Vercel Preview redeploys work correctly. 每個預覽版部署都應產生一個新的CSP 隨機數。
- POST — Rotate any test key that reached production. 即使
sk_test_*金鑰也應該在生產曝光後輪換。
v0 特定的問題(3 項)
v0 的編輯器到儲存庫匯出的獨特模式:
dangerouslySetInnerHTMLcan come back during design iterations. Review each exported version and replace any occurrences with sanitized alternatives (likereact-markdownwithremark).- Exported middleware is sometimes incomplete. v0 的
src/middleware.ts匯出可能缺少CSP 或HSTS。部署前驗證其是否完整。 - Server Actions don't automatically verify auth. v0 產生沒有內建身份驗證檢查的伺服器操作。手動將
const { user } = await supabase.auth.getUser()新增至每個狀態變更伺服器操作。
後續步驟
檢查 general vibe coding security checklist 是否有 51 個交叉工具項目。然後查看 step-by-step hardening 以了解有關 CSP、RLS 和伺服器操作安全性的更深入模式。
