認証ミドルウェア
tRPCミドルウェアを使って認証チェックを実装し、APIプロシージャを保護します。
「認証ミドルウェア」はCoddyKit上の無料tRPC End-to-End Type Safe APIsレッスンです。 これはレッスン2/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはtRPC End-to-End Type Safe APIs学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 tRPC End-to-End Type Safe APIsコースには全4レッスンが含まれています。
このレッスンの一部はまだ翻訳されておらず、英語で表示されています。
Protect Your API with Auth
Welcome to this lesson on tRPC authentication middleware! Securing your API is crucial to ensure only authorized users can access sensitive data or perform critical actions.
Middleware in tRPC provides an elegant way to centralize these security checks before any procedure runs.
Why Auth Middleware?
Using middleware for authentication offers significant advantages:
- Centralized Logic: Define authentication rules once and apply them everywhere.
- Reduced Duplication: Avoid writing the same security checks in every API procedure.
- Clean Code: Keep your business logic separate from security concerns.
- Consistency: Ensure all protected endpoints adhere to the same security standards.
Authentication Basics
Before implementing, let's briefly recall common authentication methods:
- Tokens: Such as JWTs (JSON Web Tokens) or API keys, typically sent in an
Authorizationheader. - Sessions: Often managed with cookies, where the server stores session data and the client sends a session ID.
Our middleware will be responsible for validating these credentials.
Context for User Data
Remember that the tRPC context is an object available to all procedures, carrying request-specific data. For authentication, this means our createContext function (from a previous lesson) should parse incoming authentication information (e.g., from headers) and populate the context with user data if available.
Our middleware will then *read* this user data from the context.
Building Auth Middleware
tRPC's t.middleware() function is where the magic happens. It takes an asynchronous function that receives an object with ctx (the context) and next (a function to call the next middleware or the procedure itself).
Inside, you'll check for authentication. If successful, you call next(). If not, you throw a TRPCError.
Simple Authentication Middleware
Here's a runnable TypeScript example that simulates a basic authentication middleware. It checks if a user object exists in the context.
class TRPCError extends Error {
code: string;
constructor(opts: { code: string }) {
super(`TRPCError: ${opts.code}`);
this.code = opts.code;
}
}
type MockContext = { user?: { id: string; name: string } };
type MiddlewareFn = (opts: { ctx: MockContext; next: Function }) => Promise<any>;
const isAuthenticated: MiddlewareFn = async ({ ctx, next }) => {
if (!ctx.user) {
throw new TRPCError({ code: 'UNAUTHORIZED' });
}
return next({
ctx: {
...ctx,
user: ctx.user,
},
});
};
async function runMiddlewareDemo() {
console.log("--- Test with authenticated user ---");
try {
await isAuthenticated({
ctx: { user: { id: "123", name: "Alice" } },
next: async (opts: { ctx: MockContext }) => {
console.log("Middleware passed. User:", opts.ctx.user?.name);
return "Success";
}
});
} catch (error) {
console.error("Error:", error instanceof TRPCError ? error.code : String(error));
}
console.log("\n--- Test with unauthenticated user ---");
try {
await isAuthenticated({
ctx: {}, // No user in context
next: async (opts: { ctx: MockContext }) => {
console.log("Middleware passed (should not happen)");
return "Success";
}
});
} catch (error) {
console.error("Error:", error instanceof TRPCError ? error.code : String(error));
}
}
runMiddlewareDemo();Applying Middleware to Procedures
Once defined, you can apply middleware using the .use() method. This can be done on individual procedures or even entire routers to protect multiple procedures at once.
Middleware can also be chained together, allowing you to combine multiple checks (e.g., authentication then authorization).
A Protected Query Example
Here's how you might apply the isAuthenticated middleware to a specific query procedure. The ctx.user will be guaranteed to exist inside the procedure if the middleware passes.
import { t } from './trpc'; // Your tRPC instance
import { isAuthenticated } from './middleware'; // Your auth middleware
// Imagine 'z' is imported for input validation from Zod
// import { z } from 'zod';
const appRouter = t.router({
publicGreeting: t.procedure
.query(() => {
return "Hello, stranger!";
}),
protectedGreeting: t.procedure
.use(isAuthenticated) // Apply the middleware here
.query(({ ctx }) => {
// ctx.user is guaranteed to exist here due to middleware
return `Welcome, ${ctx.user.name}! You are authenticated.`;
}),
});
// This is a conceptual snippet and not runnable standalone.Handling Unauthorized Access
When the middleware detects an unauthenticated request and throws a TRPCError (e.g., with code: 'UNAUTHORIZED'), tRPC automatically catches this error.
It then sends a standardized error response to the client, allowing your frontend application to gracefully handle the unauthorized access, perhaps by redirecting the user to a login page.
Test Your Auth Middleware Knowledge
You have an isAdmin middleware. You want to protect all procedures within an adminRouter so only administrators can access them. Which is the correct way to apply the middleware?
Authentication Middleware Recap
You've learned how to implement authentication checks using tRPC middleware!
- Authentication middleware centralizes security logic.
- It leverages the tRPC context to access user information.
- You define it using
t.middleware(). - You apply it to procedures or entire routers using
.use(). TRPCErrorensures proper error handling for unauthorized requests.
Next, explore how to build custom middleware chains for more complex scenarios!
よくある質問
「認証ミドルウェア」レッスンは無料ですか?
はい。「認証ミドルウェア」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、tRPC End-to-End Type Safe APIsコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 tRPC End-to-End Type Safe APIsコースには全4レッスンが含まれています。
「認証ミドルウェア」で何を学びますか?
tRPCミドルウェアを使って認証チェックを実装し、APIプロシージャを保護します。 ブラウザで直接実行するハンズオンコードでtRPC End-to-End Type Safe APIsを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。
tRPC End-to-End Type Safe APIsを始めるのに経験は必要ですか?
事前経験は必要ありません。CoddyKitのtRPC End-to-End Type Safe APIsは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン2/4です。
「認証ミドルウェア」レッスンにはどのくらい時間がかかりますか?
ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。
このtRPC End-to-End Type Safe APIsレッスンでコードを書いて実行できますか?
はい。すべてのtRPC End-to-End Type Safe APIsレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。