The security check
Before you publish, crisp checks your app for common security problems, such as keys in the code or data anyone can change. A critical problem blocks publishing until it is fixed, and one click asks crisp to fix it.
Updated
An app that stores other people's data needs to keep it safe. The security check looks for the problems that most often expose people's data.
What it checks#
- Secret keys written into the code, where anyone could find them.
- Data that anyone can read or change without signing in.
- Unsafe ways of building database queries, web pages or commands from what people type.
- Libraries your app uses that have known security holes.
- Risky settings, or debugging features left switched on.
When it runs#
- Every time you open Publish, before you can publish.
- Whenever you want: open the More menu in the top bar and choose Security check.
Read the report#
Problems are grouped by how serious they are: Critical, High, Medium and Low. Each one has a short title, an explanation in plain words, and the file and line where it is.
| Level | What it means for publishing |
|---|---|
| Critical | Publishing is blocked until it is fixed. |
| High and Medium | Worth fixing first. You can still publish. |
| Low | Worth knowing. Usually nothing to do. |
Fix a problem#
- Press Fix with crisp on one problem, or Fix all for every problem in the report.
- crisp switches to the chat and starts working on it, like any other request. If a build is already running, the request waits in the message box until you send it.
- When the build is done, press Check again to run the check on the new code.
Keys belong in Secrets#
The most common problem is a key written into the code. Keep keys for other services in Secrets instead. See Give your app a key.
Related pages
Something wrong or missing on this page? Tell us. A person reads every message.
Report a problem