दस्तावेज़/सीक्रेट सुरक्षा

सीक्रेट सुरक्षा

कड़े secure coding rules, zero-trust cloud storage models, और local secret protection mechanisms.

ज़ीरो-सीक्रेट नीति

सुरक्षा VibeBasket की मुख्य प्राथमिकताओं में से एक है। Installed MCP servers द्वारा उपयोग किए जाने वाले OpenAI या GitHub API tokens जैसे संवेदनशील keys कभी भी bundle database के भीतर transit या cache नहीं होते।

ज़ीरो-ट्रस्ट क्लाउड नीति

Bundle manifests कभी भी end-user runtime secrets को शामिल नहीं करते। Hosted app केवल selected catalog metadata और वैकल्पिक रूप से encrypted admin backup-storage credentials रखता है, लेकिन runtime पर MCPs या agent tools द्वारा उपयोग की जाने वाली API keys नहीं रखता।

इसके बजाय, bundle को local apply करते समय CLI target credential keys को parse करता है और operator को local terminal में सुरक्षित रूप से उन्हें inject करने के लिए prompt करता है। Hosted app इन runtime values को कभी नहीं देखता।

इसके बाद secret handling target adapter पर निर्भर करती है। अधिकांश IDEs को local config files में inline MCP env या header values चाहिए होती हैं, इसलिए CLI उन secrets को operator की मशीन पर resolve करता है और केवल उसी मशीन की local IDE config में लिखता है। Remote MCP auth headers के लिए Codex आंशिक exception है: जब इसका native config format environment-key reference support करता है, तो VibeBasket raw token को TOML में serialize करने के बजाय वही reference इस्तेमाल करता है।

रेट लिमिटिंग

सभी public API endpoints sliding-window rate limiter से संरक्षित हैं, जिसमें per-IP tracking और automatic garbage collection शामिल है। Proxy-derived IP headers पर तभी भरोसा किया जाता है जब self-hoster स्पष्ट रूप से proxy trust सक्षम करे।

API endpoint rate limits
EndpointLimit
/api/health120/min
/api/catalog120/min
/api/auth/*60/min
/api/bundle/[id]60/min
/api/stacks30/min
/api/admin/stats30/min
/api/catalog/status5/min
/api/bundle POST20/min

सुरक्षा हेडर्स

सभी responses hardened security headers के साथ आते हैं। Production में HTML routes को nonce-based Content-Security-Policy मिलता है, ताकि Next.js सुरक्षित रूप से hydrate हो सके और blanket inline-script execution की गुंजाइश न बने; साथ ही पूरे deployment पर HSTS लागू रहता है।

Security response headers
HeaderValue
X-Frame-OptionsDENY
X-Content-Type-Optionsnosniff
Referrer-Policystrict-origin-when-cross-origin
X-Permitted-Cross-Domain-Policiesnone
X-Download-Optionsnoopen
Permissions-Policycamera=(), microphone=(), geolocation=()
Strict-Transport-Securitymax-age=63072000; includeSubDomains; preload
Content-Security-Policydefault-src 'self'; script-src 'self' 'nonce-<request-nonce>' 'strict-dynamic' 'wasm-unsafe-eval'; style-src 'self' 'unsafe-inline'; object-src 'none'; manifest-src 'self'; frame-ancestors 'none'

एडमिन पैनल सुरक्षा

/admin पर मौजूद admin dashboard OAuth-authenticated sessions के पीछे सुरक्षित है। Access केवल ADMIN_OAUTH_EMAILS environment variable में सूचीबद्ध email addresses तक सीमित है, और केवल verified allowlisted emails को admin role मिलता है।

Admin panel security controls
FeatureDescription
Catalog SyncUpstream sources से registry synchronization को manually trigger करता है।
Backup Mgmtकिसी भी configured storage backend पर database backups create, list, download और restore करता है।
FTS5 Index HealthIntegrity जाँचने के लिए full-text search index row count को catalog table से compare करता है।
DB Health CheckDatabase integrity diagnostics चलाता है और corruption को जल्दी पहचानता है।
Force CleanupExpired bundles, stale sessions, verification tokens और पुराने sync records को purge करके vacuum चलाता है।
User OverviewRegistered user counts, saved stack telemetry और popularity leaderboards का निरीक्षण करता है।
Admin EmailsComma-separated admin email allowlist को site config के रूप में persist करता है।

सभी admin actions केवल server-side चलते हैं और verified administrator session की आवश्यकता होती है। /api/admin/stats endpoint पर rate limit 30 requests प्रति minute है।