Best practices for authorizing server actions
Unanswered
Saltwater Crocodile posted this in #help-forum
Saltwater CrocodileOP
Hi, I have a middleware in nextjs that authorizes users, and redirects them to the correct page if they try to access unauthorized pages.
If a logged out user tries to access any page aside from the login page they are redirected
if a normal user tries to access pages under
Inside my pages like
I noticed that the server actions run on the same URL as the page that's calling them, for example the action inside the deals page has this url
If a logged out user tries to access any page aside from the login page they are redirected
if a normal user tries to access pages under
/admin they are redirected to their user portalInside my pages like
/admin/users and /admin/deals I have server actions to mutate dataI noticed that the server actions run on the same URL as the page that's calling them, for example the action inside the deals page has this url
/admin/deals?rsc=W78UG-asdf2123F so I thought maybe I could remove the authorization check inside my server action since that check does the same thing as the one inside my middleware but I am not sure if I am missing something1 Reply
@Saltwater Crocodile Hi, I have a middleware in nextjs that authorizes users, and redirects them to the correct page if they try to access unauthorized pages.
If a logged out user tries to access any page aside from the login page they are redirected
if a normal user tries to access pages under `/admin` they are redirected to their user portal
Inside my pages like `/admin/users` and `/admin/deals` I have server actions to mutate data
I noticed that the server actions run on the same URL as the page that's calling them, for example the action inside the deals page has this url `/admin/deals?rsc=W78UG-asdf2123F` so I thought maybe I could remove the authorization check inside my server action since that check does the same thing as the one inside my middleware but I am not sure if I am missing something
you are right: move the permission check to the server action as well. Technically it’s just a normal endpoint that you can call independently of the page and auth status. So secure it. Your middleware alr does a bit, but making it secure in the server action makes still sense tho