Nuxt · Runtime config
NUXT0054Do not expose secrets in runtimeConfig.public
Flags secret in public config in Nuxt runtime code before it leaks into runtime behavior.
vite-doctor/nuxtruntime-configerrorSuggestion
Why it happens
Secrets that reach public runtime config or client bundles can be exposed to every visitor and crawler.
Fix
Move secrets to private runtimeConfig and read them only on the server.
Example
Avoid secret in public config
Before
export default defineNuxtConfig({
runtimeConfig: {
public: { apiSecret: process.env.API_SECRET },
},
})
After
export default defineNuxtConfig({
runtimeConfig: {
apiSecret: process.env.API_SECRET,
public: { apiBase: '/api' },
},
})
Verify the fix
Run only this rule after editing so the report stays focused on the diagnostic you are closing:
pnpm nuxt doctor --rules nuxt/runtime/no-secret-in-public-config