Vite · VITE0009
Do not read secret-looking env vars in client code
Flags client secret pattern in Vite env code before it leaks into runtime behavior.
Run this rule
pnpm vite-doctor . --framework vite --rules vite/env/no-client-secret-pattern
Why it matters
Secrets that reach public runtime config or client bundles can be exposed to every visitor and crawler.
Recommended fix
Remove client secret pattern, or move it to the Vite runtime/API that owns that behavior.
Useful links
Example
Keep secret env vars server-only
Before
const token = import.meta.env.VITE_API_SECRET
After
const apiBase = import.meta.env.VITE_PUBLIC_API_BASE