feat: improve form results and harden secrets
This commit is contained in:
@@ -34,4 +34,29 @@ You can check out [the Next.js GitHub repository](https://github.com/vercel/next
|
||||
The easiest way to deploy your Next.js app is to use the [Vercel Platform](https://vercel.com/new?utm_medium=default-template&filter=next.js&utm_source=create-next-app&utm_campaign=create-next-app-readme) from the creators of Next.js.
|
||||
|
||||
Check out our [Next.js deployment documentation](https://nextjs.org/docs/app/building-your-application/deploying) for more details.
|
||||
|
||||
## Secret safety
|
||||
|
||||
- Keep credentials in `.env` or `.env.local`. Never prefix a credential with
|
||||
`NEXT_PUBLIC_`.
|
||||
- Restrict local access before starting the app:
|
||||
|
||||
```bash
|
||||
chmod 600 .env .env.local
|
||||
```
|
||||
|
||||
- Scan tracked files and Git history before deployment:
|
||||
|
||||
```bash
|
||||
bun run secrets:scan
|
||||
```
|
||||
|
||||
- Deploy with Docker Compose so `.env` is injected only when the container
|
||||
starts. Environment files are excluded from the Docker build context.
|
||||
- Give the Discord bot only the permissions it needs. Avoid the Administrator
|
||||
permission.
|
||||
- Rotate every credential from `.env` if an environment file, build context,
|
||||
builder cache, log, or host may have been shared. If prior exposure cannot be
|
||||
ruled out, treat the credentials as exposed.
|
||||
|
||||
# erika
|
||||
|
||||
Reference in New Issue
Block a user