सीक्रेट सुरक्षा
कड़े secure coding rules, zero-trust cloud storage models, और local secret protection mechanisms.
ज़ीरो-सीक्रेट नीति
सुरक्षा VibeBasket की मुख्य प्राथमिकताओं में से एक है। Installed MCP servers द्वारा उपयोग किए जाने वाले OpenAI या GitHub API tokens जैसे संवेदनशील keys कभी भी bundle database के भीतर transit या cache नहीं होते।
ज़ीरो-ट्रस्ट क्लाउड नीति
Bundle manifests कभी भी end-user runtime secrets को शामिल नहीं करते। Hosted app केवल selected catalog metadata और वैकल्पिक रूप से encrypted admin backup-storage credentials रखता है, लेकिन runtime पर MCPs या agent tools द्वारा उपयोग की जाने वाली API keys नहीं रखता।
इसके बजाय, bundle को local apply करते समय CLI target credential keys को parse करता है और operator को local terminal में सुरक्षित रूप से उन्हें inject करने के लिए prompt करता है। Hosted app इन runtime values को कभी नहीं देखता।
इसके बाद secret handling target adapter पर निर्भर करती है। अधिकांश IDEs को local config files में inline MCP env या header values चाहिए होती हैं, इसलिए CLI उन secrets को operator की मशीन पर resolve करता है और केवल उसी मशीन की local IDE config में लिखता है। Remote MCP auth headers के लिए Codex आंशिक exception है: जब इसका native config format environment-key reference support करता है, तो VibeBasket raw token को TOML में serialize करने के बजाय वही reference इस्तेमाल करता है।
रेट लिमिटिंग
सभी public API endpoints sliding-window rate limiter से संरक्षित हैं, जिसमें per-IP tracking और automatic garbage collection शामिल है। Proxy-derived IP headers पर तभी भरोसा किया जाता है जब self-hoster स्पष्ट रूप से proxy trust सक्षम करे।
| Endpoint | Limit |
|---|---|
| /api/health | 120/min |
| /api/catalog | 120/min |
| /api/auth/* | 60/min |
| /api/bundle/[id] | 60/min |
| /api/stacks | 30/min |
| /api/admin/stats | 30/min |
| /api/catalog/status | 5/min |
| /api/bundle POST | 20/min |
सुरक्षा हेडर्स
सभी responses hardened security headers के साथ आते हैं। Production में HTML routes को nonce-based Content-Security-Policy मिलता है, ताकि Next.js सुरक्षित रूप से hydrate हो सके और blanket inline-script execution की गुंजाइश न बने; साथ ही पूरे deployment पर HSTS लागू रहता है।
| Header | Value |
|---|---|
| X-Frame-Options | DENY |
| X-Content-Type-Options | nosniff |
| Referrer-Policy | strict-origin-when-cross-origin |
| X-Permitted-Cross-Domain-Policies | none |
| X-Download-Options | noopen |
| Permissions-Policy | camera=(), microphone=(), geolocation=() |
| Strict-Transport-Security | max-age=63072000; includeSubDomains; preload |
| Content-Security-Policy | default-src 'self'; script-src 'self' 'nonce-<request-nonce>' 'strict-dynamic' 'wasm-unsafe-eval'; style-src 'self' 'unsafe-inline'; object-src 'none'; manifest-src 'self'; frame-ancestors 'none' |
एडमिन पैनल सुरक्षा
/admin पर मौजूद admin dashboard OAuth-authenticated sessions के पीछे सुरक्षित है। Access केवल ADMIN_OAUTH_EMAILS environment variable में सूचीबद्ध email addresses तक सीमित है, और केवल verified allowlisted emails को admin role मिलता है।
| Feature | Description |
|---|---|
| Catalog Sync | Upstream sources से registry synchronization को manually trigger करता है। |
| Backup Mgmt | किसी भी configured storage backend पर database backups create, list, download और restore करता है। |
| FTS5 Index Health | Integrity जाँचने के लिए full-text search index row count को catalog table से compare करता है। |
| DB Health Check | Database integrity diagnostics चलाता है और corruption को जल्दी पहचानता है। |
| Force Cleanup | Expired bundles, stale sessions, verification tokens और पुराने sync records को purge करके vacuum चलाता है। |
| User Overview | Registered user counts, saved stack telemetry और popularity leaderboards का निरीक्षण करता है। |
| Admin Emails | Comma-separated admin email allowlist को site config के रूप में persist करता है। |
सभी admin actions केवल server-side चलते हैं और verified administrator session की आवश्यकता होती है। /api/admin/stats endpoint पर rate limit 30 requests प्रति minute है।