Vite · Security
VITE0009Do not read secret-looking env vars in client code
Flags client secret pattern in Vite env code before it leaks into runtime behavior.
vite-doctor/vitesecurityerrorNo fix
Why it happens
Secrets that reach public runtime config or client bundles can be exposed to every visitor and crawler.
Fix
Remove client secret pattern, or move it to the Vite runtime/API that owns that behavior.
Example
Keep secret env vars server-only
Before
const token = import.meta.env.VITE_API_SECRET
After
const apiBase = import.meta.env.VITE_PUBLIC_API_BASE
Verify the fix
Run only this rule after editing so the report stays focused on the diagnostic you are closing:
pnpm vite-doctor . --framework vite --rules vite/env/no-client-secret-pattern