Case: Splitting Staging From Prod Stopped a Search-Engine Leak
A staging copy at staging.client.com shared prod's DB and was fully indexable. It leaked 1,100 draft URLs and an exposed admin login into Google.
Environment-isolation SOP:
— Step 1: Give staging its own database and its own credentials — never share prod's.
— Step 2: Gate staging behind HTTP basic auth, allowlist by IP.
— Step 3: Serve X-Robots-Tag: noindex, nofollow on every staging response at the edge.
— Step 4: Rotate any secret that ever lived in both environments.
— Step 5: Submit a removal request for the 1,100 leaked URLs, then re-scan with a site: query.
Outcome: Indexed staging URLs went from 1,100 to 0 within 9 days. Shared-credential exposure closed after rotation. Staging now returns 401 to anyone outside the allowlist.
Run this every time.
Lockdown Ledger
@LockdownLedger
Case: Splitting Staging From Prod Stopped a Search-Engine Leak
Этот пост опубликован в Telegram-канале Lockdown Ledger. Подписаться можно по ссылке: @LockdownLedger.