0Pricing
tRPC End-to-End Type Safe APIs · Leçon

Intergiciel d’authentification

Implémentez des vérifications d’authentification avec l’intergiciel tRPC afin de protéger vos procédures d’API.

Intergiciel d’authentification est une leçon tRPC End-to-End Type Safe APIs gratuite sur CoddyKit. Ceci est la leçon 2 sur 4. Tu peux lire la leçon complète ci-dessous gratuitement — puis la pratiquer en direct dans le navigateur avec un éditeur de code intégré et un tuteur IA 24/7. Elle fait partie du parcours d'apprentissage tRPC End-to-End Type Safe APIs, et ta progression se synchronise sur le web et l'application CoddyKit. Le cours tRPC End-to-End Type Safe APIs comprend 4 leçons au total.

Certaines parties de cette leçon n'ont pas encore été traduites et s'affichent en anglais.

Protect Your API with Auth

Welcome to this lesson on tRPC authentication middleware! Securing your API is crucial to ensure only authorized users can access sensitive data or perform critical actions.

Middleware in tRPC provides an elegant way to centralize these security checks before any procedure runs.

Why Auth Middleware?

Using middleware for authentication offers significant advantages:

  • Centralized Logic: Define authentication rules once and apply them everywhere.
  • Reduced Duplication: Avoid writing the same security checks in every API procedure.
  • Clean Code: Keep your business logic separate from security concerns.
  • Consistency: Ensure all protected endpoints adhere to the same security standards.

Authentication Basics

Before implementing, let's briefly recall common authentication methods:

  • Tokens: Such as JWTs (JSON Web Tokens) or API keys, typically sent in an Authorization header.
  • Sessions: Often managed with cookies, where the server stores session data and the client sends a session ID.

Our middleware will be responsible for validating these credentials.

Context for User Data

Remember that the tRPC context is an object available to all procedures, carrying request-specific data. For authentication, this means our createContext function (from a previous lesson) should parse incoming authentication information (e.g., from headers) and populate the context with user data if available.

Our middleware will then *read* this user data from the context.

Building Auth Middleware

tRPC's t.middleware() function is where the magic happens. It takes an asynchronous function that receives an object with ctx (the context) and next (a function to call the next middleware or the procedure itself).

Inside, you'll check for authentication. If successful, you call next(). If not, you throw a TRPCError.

Simple Authentication Middleware

Here's a runnable TypeScript example that simulates a basic authentication middleware. It checks if a user object exists in the context.

class TRPCError extends Error {
  code: string;
  constructor(opts: { code: string }) {
    super(`TRPCError: ${opts.code}`);
    this.code = opts.code;
  }
}

type MockContext = { user?: { id: string; name: string } };
type MiddlewareFn = (opts: { ctx: MockContext; next: Function }) => Promise<any>;

const isAuthenticated: MiddlewareFn = async ({ ctx, next }) => {
  if (!ctx.user) {
    throw new TRPCError({ code: 'UNAUTHORIZED' });
  }
  return next({
    ctx: {
      ...ctx,
      user: ctx.user,
    },
  });
};

async function runMiddlewareDemo() {
  console.log("--- Test with authenticated user ---");
  try {
    await isAuthenticated({
      ctx: { user: { id: "123", name: "Alice" } },
      next: async (opts: { ctx: MockContext }) => {
        console.log("Middleware passed. User:", opts.ctx.user?.name);
        return "Success";
      }
    });
  } catch (error) {
    console.error("Error:", error instanceof TRPCError ? error.code : String(error));
  }

  console.log("\n--- Test with unauthenticated user ---");
  try {
    await isAuthenticated({
      ctx: {}, // No user in context
      next: async (opts: { ctx: MockContext }) => {
        console.log("Middleware passed (should not happen)");
        return "Success";
      }
    });
  } catch (error) {
    console.error("Error:", error instanceof TRPCError ? error.code : String(error));
  }
}

runMiddlewareDemo();

Applying Middleware to Procedures

Once defined, you can apply middleware using the .use() method. This can be done on individual procedures or even entire routers to protect multiple procedures at once.

Middleware can also be chained together, allowing you to combine multiple checks (e.g., authentication then authorization).

A Protected Query Example

Here's how you might apply the isAuthenticated middleware to a specific query procedure. The ctx.user will be guaranteed to exist inside the procedure if the middleware passes.

import { t } from './trpc'; // Your tRPC instance
import { isAuthenticated } from './middleware'; // Your auth middleware

// Imagine 'z' is imported for input validation from Zod
// import { z } from 'zod';

const appRouter = t.router({
  publicGreeting: t.procedure
    .query(() => {
      return "Hello, stranger!";
    }),
  
  protectedGreeting: t.procedure
    .use(isAuthenticated) // Apply the middleware here
    .query(({ ctx }) => {
      // ctx.user is guaranteed to exist here due to middleware
      return `Welcome, ${ctx.user.name}! You are authenticated.`;
    }),
});

// This is a conceptual snippet and not runnable standalone.

Handling Unauthorized Access

When the middleware detects an unauthenticated request and throws a TRPCError (e.g., with code: 'UNAUTHORIZED'), tRPC automatically catches this error.

It then sends a standardized error response to the client, allowing your frontend application to gracefully handle the unauthorized access, perhaps by redirecting the user to a login page.

Test Your Auth Middleware Knowledge

You have an isAdmin middleware. You want to protect all procedures within an adminRouter so only administrators can access them. Which is the correct way to apply the middleware?

Authentication Middleware Recap

You've learned how to implement authentication checks using tRPC middleware!

  • Authentication middleware centralizes security logic.
  • It leverages the tRPC context to access user information.
  • You define it using t.middleware().
  • You apply it to procedures or entire routers using .use().
  • TRPCError ensures proper error handling for unauthorized requests.

Next, explore how to build custom middleware chains for more complex scenarios!

Questions Fréquemment Posées

La leçon « Intergiciel d’authentification » est-elle gratuite ?

Oui — le texte complet de « Intergiciel d’authentification » est gratuit à lire ici sur le web. Pour la pratiquer de manière interactive (un éditeur de code intégré et un tuteur IA 24/7) et déverrouiller le reste du cours tRPC End-to-End Type Safe APIs, passe à CoddyKit PRO. Le cours tRPC End-to-End Type Safe APIs comprend 4 leçons au total.

Qu'est-ce que j'apprendrai dans « Intergiciel d’authentification » ?

Implémentez des vérifications d’authentification avec l’intergiciel tRPC afin de protéger vos procédures d’API. Tu pratiques tRPC End-to-End Type Safe APIs avec du code pratique que tu exécutes directement dans le navigateur, et un tuteur IA 24/7 répond à tes questions au fur et à mesure que tu avances dans la leçon.

Dois-je avoir de l'expérience pour commencer tRPC End-to-End Type Safe APIs ?

Aucune expérience préalable n'est requise. tRPC End-to-End Type Safe APIs sur CoddyKit est structuré pour les débutants jusqu'aux apprenants avancés, donc tu peux commencer ici ou depuis le début et avancer à ton rythme. Ceci est la leçon 2 sur 4.

Combien de temps prend la leçon « Intergiciel d’authentification » ?

La plupart des leçons CoddyKit prennent environ 5–10 minutes. Chacune est courte et interactive, tu progresses régulièrement et tu repiques exactement où tu t'es arrêté sur le web et l'app.

Peux-tu écrire et exécuter du code dans cette leçon tRPC End-to-End Type Safe APIs ?

Oui. Chaque leçon tRPC End-to-End Type Safe APIs inclut un éditeur de code intégré, tu écris et exécutes du vrai code directement dans ton navigateur et tu reçois des retours IA instantanés — aucune configuration locale requise.

Toutes les leçons de ce cours

  1. Créer le contexte tRPC
  2. Intergiciel d’authentification
  3. Chaînes d’intergiciels personnalisées
  4. Intergiciel de journalisation et de mesure des performances
← Retour à tRPC End-to-End Type Safe APIs