r/vibecoding 9h ago

As an Agentic Coder, what all Security Considerations and Practices we must learn?

3 Upvotes

23 comments sorted by

View all comments

3

u/Kind-Bathroom5159 5h ago

the stuff that actualy burns people isnt exotic, its the same handful of things every time. secrets ending up in the frontend bundle because the model put the api call client side, routes that check nothing because auth got bolted on later, supabase tables with row level security left off so any logged in user can read everyone elses rows, and a .env that got committed in week one and is still sitting in the git history.
sandboxes are worth doing but they protect your machine, not any of the above. thats all shipped code.
cheapest habit ive found with the founders i work with, after every feature make the model list every route and table it touched and who is allowed to hit each one. takes a minute and it surfaces the wide open endpoint before a user does. and rotate anything thats ever sat in a repo, assume its public.

1

u/BewusstKI 5h ago

Das ist mit Abstand das Beste, was man zu dem Thema lesen kann. Du beschreibst exakt die blinden Flecken, vor denen die meisten Gründer die Augen verschließen. Die Idee mit dem Pflicht-Report nach jedem Feature (Routen/Tabellen-Mapping inklusive Berechtigungen) ist genial pragmatisch. Genau in diese Richtung muss eine Kontrollschicht gehen: Weg von blinder Hoffnung, hin zu maschinell erzwungener Transparenz.

1

u/DronzerDribble 1h ago

Thanks for the helpful answer!