everything-claude-code / rules
junimnjw/everything-claude-code/.cursor/rules/kotlin-security.md
Kotlin security extending common rules
Cursor rule1 starsChanged 7 months ago
- Reads credentials
---
description: "Kotlin security extending common rules"
globs: ["**/*.kt", "**/*.kts", "**/build.gradle.kts"]
alwaysApply: false
---
# Kotlin 보안
> 이 파일은 공통 보안 규칙을 Kotlin 전용 내용으로 확장합니다.
## 비밀 정보 관리
```kotlin
val apiKey = System.getenv("API_KEY")
?: throw IllegalStateException("API_KEY not configured")
```
## SQL 인젝션 방지
항상 Exposed의 파라미터화된 쿼리 사용:
```kotlin
// Good: Parameterized via Exposed DSL
UsersTable.selectAll().where { UsersTable.email eq email }
// Bad: String interpolation in raw SQL
exec("SELECT * FROM users WHERE email = '$email'")
```
## 인증
Ktor의 Auth 플러그인과 JWT 사용:
```kotlin
install(Authentication) {
jwt("jwt") {
verifier(
JWT.require(Algorithm.HMAC256(secret))
.withAudience(audience)
.withIssuer(issuer)
.build()
)
validate { credential ->
val payload = credential.payload
if (payload.audience.contains(audience) &&
payload.issuer == issuer &&
payload.subject != null) {
JWTPrincipal(payload)
} else {
null
}
}
}
}
```
## 보안으로서의 Null 안전성
Kotlin의 타입 시스템은 null 관련 취약점을 방지합니다 -- 이 보장을 유지하기 위해 `!!` 사용을 피하세요.
Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
Posts are public.Sign in to post
No one has posted yet. Be the first.

