everything-claude-code / rules
junimnjw/everything-claude-code/.cursor/rules/swift-security.md
Swift security extending common rules
Cursor rule1 starsChanged 7 months ago
- Reads credentials
---
description: "Swift security extending common rules"
globs: ["**/*.swift", "**/Package.swift"]
alwaysApply: false
---
# Swift 보안
> 이 파일은 공통 보안 규칙을 Swift 전용 내용으로 확장합니다.
## 비밀 정보 관리
- 민감한 데이터(토큰, 비밀번호, 키)에는 **Keychain Services** 사용 -- `UserDefaults` 절대 사용 금지
- 빌드 시 비밀 정보에는 환경 변수 또는 `.xcconfig` 파일 사용
- 소스에 비밀 정보를 절대 하드코딩하지 않기 -- 디컴파일 도구가 쉽게 추출 가능
```swift
let apiKey = ProcessInfo.processInfo.environment["API_KEY"]
guard let apiKey, !apiKey.isEmpty else {
fatalError("API_KEY not configured")
}
```
## 전송 보안
- App Transport Security (ATS)는 기본적으로 적용 -- 비활성화하지 않기
- 중요한 엔드포인트에 인증서 피닝 사용
- 모든 서버 인증서 검증
## 입력 검증
- 인젝션 방지를 위해 표시 전 모든 사용자 입력 살균
- 강제 언래핑 대신 검증과 함께 `URL(string:)` 사용
- 처리 전 외부 소스(API, 딥 링크, 클립보드)의 데이터 검증
Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
Posts are public.Sign in to post
No one has posted yet. Be the first.

