- Provider keys live only in environment variables.
- .env is ignored.
- .env.example contains placeholders only.
- Frontend VITE_* variables must never contain provider secrets.
The production lexical strategy is per-tenant BM25.
A global BM25 index followed by metadata filtering is not an accepted production design.
Normal user operations should carry the user's authorization context so RLS can enforce ownership.
Service-role credentials are restricted to explicitly trusted operations and do not prove that RLS is working.
Retrieved document content is untrusted input.
Later production generation must:
- keep system/developer instructions separate from retrieved text;
- delimit evidence clearly;
- prevent document text from becoming executable instructions;
- test adversarial prompt-injection documents.
The current API validates query length and rejects empty queries.
Current API controls include PDF type validation, upload-size limits, query-size limits, and safe error responses with server-side exception logging. Remaining production hardening includes request-size limits, rate limits, quota enforcement, and structured secret-safe logging.
Before accepting real multi-user data:
- authenticate as User A;
- attempt to access User B's document/query/source;
- verify denial;
- repeat through the real API path;
- verify RLS independently.