feat: improve form results and harden secrets

This commit is contained in:
2026-07-30 14:48:46 +07:00 Unverified
parent 6b0440602b
commit a014f72d0f
32 changed files with 471 additions and 11 deletions
+25
View File
@@ -34,4 +34,29 @@ You can check out [the Next.js GitHub repository](https://github.com/vercel/next
The easiest way to deploy your Next.js app is to use the [Vercel Platform](https://vercel.com/new?utm_medium=default-template&filter=next.js&utm_source=create-next-app&utm_campaign=create-next-app-readme) from the creators of Next.js.
Check out our [Next.js deployment documentation](https://nextjs.org/docs/app/building-your-application/deploying) for more details.
## Secret safety
- Keep credentials in `.env` or `.env.local`. Never prefix a credential with
`NEXT_PUBLIC_`.
- Restrict local access before starting the app:
```bash
chmod 600 .env .env.local
```
- Scan tracked files and Git history before deployment:
```bash
bun run secrets:scan
```
- Deploy with Docker Compose so `.env` is injected only when the container
starts. Environment files are excluded from the Docker build context.
- Give the Discord bot only the permissions it needs. Avoid the Administrator
permission.
- Rotate every credential from `.env` if an environment file, build context,
builder cache, log, or host may have been shared. If prior exposure cannot be
ruled out, treat the credentials as exposed.
# erika