Security
Fixing issues
Three ways to fix what the scan found. Each fix is a new version, scanned again.
Every issue in the app's security review (Open review on the app's Security card) offers one or more of these fixes. Each fix becomes a new version and is scanned again, so an issue only closes when the fix really worked.
1. Paste the fix prompt into your AI tool
Every issue comes with a fix prompt written for your AI tool. When you deploy from a chat, your AI tool already has them. Ask:
Fix the security issues Inhaus found and redeploy.Or copy the prompt from the security review, for example:
Move the HubSpot private app token in src/api.js (line 12) into an Inhaus secret
called HUBSPOT_PRIVATE_APP_TOKEN and read it from env.HUBSPOT_PRIVATE_APP_TOKEN.
Then redeploy.2. Move to secrets (one click, no AI)
For keys found in code, choose Move to secrets. Inhaus stores the value as a secret, rewrites the line to read it from env, and deploys a new version.
3. Ask AI to write a fix
Choose Fix with AI. Inhaus sends the affected files (secret values removed) and the issue to an AI model, which writes a code change and a short explanation. You can add a note to guide it.
Nothing is deployed until you have seen the change. The review shows the explanation and the diff. Choose Apply and deploy to deploy it as a new version, or close it.
Domains that are not allowed
For a call to a website that is not on your workspace's list, you have two choices:
- Remove the call with one of the fixes above.
- Keep it and ask an admin. Choose Ask admin to allow and give a reason. Admins see it next to the request. See Allowed domains.