The security pass before anything is public
You have run the four review lenses three times. This is the pass that is specific to going public, and it takes about an hour.
What changes when the repository is public
Everything is readable, including the history. Not just what is there now. git log -p through your key pattern, once, before you make it public — and if anything turns up, rotate rather than rewrite. Rewriting history on a repository that has been cloned does not un-clone it.
The URL is discoverable. Your proxy will receive traffic you did not send. That is the moment every clamp and allowlist from course 2 stops being pedantry: limit clamped server-side, symbols against an allowlist, filter fields from a closed set.
Your key pays for strangers' requests. This is the sentence to sit with. A public deployment with an open proxy is a free market-data API that you are funding, and the first thing that finds it will be a bot rather than a person.
Rate-limit your own proxy
The upstream API limits you. Nothing limits whoever is calling your deployment. Add a per-IP limit at the proxy — a few dozen requests a minute is generous for a human and useless for a scraper.
This is not optional once the URL is public, and it is the piece most personal projects skip. It costs one middleware and it is the difference between a tool and a donation.
The specific list, before you flip the switch
- No key in the working tree, and none in the history.
- Every proxy parameter validated or dropped; nothing forwarded blindly.
limitand any range parameter clamped server-side.- A per-IP rate limit on the proxy.
- Store queries scoped by user, with the cross-user test asserting 404 (course 4).
- No stack traces or upstream error bodies reaching the client.
- Security headers, and no
Access-Control-Allow-Origin: *on your proxy. - Dependency audit clean, or its exceptions written down.
Eight items. Run it as a list, not from memory, because the one you skip is the one that was not obvious that day.
Then ask something adversarial
Give your assistant the proxy route and the deployment URL shape and ask: "how would you abuse this?"
Read the answers sceptically — some will be wrong or already handled. The value is that it enumerates a category you were not thinking about, and enumeration is the part humans are bad at when reviewing their own work.
Try it now
Run the eight-item list and write the results in REVIEW.md with a date. Then deliberately hammer your own deployment with a loop for thirty seconds and watch the meter. If nothing stops you, nothing will stop anyone else.