Ochrona tras i danych
Zaimplementuj middleware i kontrole po stronie serwera, aby chronić wybrane trasy i dane na podstawie statusu uwierzytelnienia użytkownika
Ochrona tras i danych to bezpłatna lekcja Next.js 15 Fullstack (App Router + Server Actions) na CoddyKit. To lekcja 3 z 6. Możesz przeczytać całą lekcję poniżej za darmo — a potem ćwiczyć ją interaktywnie w przeglądarce z wbudowanym edytorem kodu i tutorem AI dostępnym 24/7. To część ścieżki edukacyjnej Next.js 15 Fullstack (App Router + Server Actions), a Twój postęp synchronizuje się między webem a aplikacją CoddyKit. Kurs Next.js 15 Fullstack (App Router + Server Actions) zawiera 6 lekcji w sumie.
Części tej lekcji nie zostały jeszcze przetłumaczone i są wyświetlane po angielsku.
Why Protect Routes & Data?
In any application, not all information or features should be accessible to everyone. Protecting routes and data is crucial for security.
- Route Protection: Prevents unauthorized users from even reaching certain pages (e.g., an admin dashboard).
- Data Protection: Ensures users can only view or modify data they are authorized to access (e.g., a user's own profile, not someone else's).
This lesson explores how Next.js helps you enforce these rules on the server side.
Introducing Next.js Middleware
Next.js Middleware allows you to run code before a request is completed. It's like a gatekeeper for your application.
Middleware runs on the Edge Runtime, providing extremely fast execution. It can:
- Redirect users to different pages.
- Rewrite URLs.
- Add/modify request or response headers.
- Perform authentication checks.
Setting Up Middleware
To use middleware, create a file named middleware.ts (or .js) at the root of your project or within the src or app directory.
This file exports a function that receives the incoming request and returns a response.
import { NextResponse } from 'next/server';
import type { NextRequest } from 'next/server';
export function middleware(request: NextRequest) {
// Your protection logic goes here
console.log('Middleware executed for:', request.url);
return NextResponse.next();
}
// Configure which paths the middleware applies to
export const config = {
matcher: ['/dashboard/:path*', '/profile'],
};
Redirecting Unauthorized Users
A common use case for middleware is to redirect users who are not authenticated away from protected routes.
You can check for an authentication token or session cookie and, if missing, redirect them to a login page.
import { NextResponse } from 'next/server';
import type { NextRequest } from 'next/server';
export function middleware(request: NextRequest) {
const isAuthenticated = request.cookies.has('session_token');
const isLoginPage = request.nextUrl.pathname.startsWith('/login');
if (!isAuthenticated && !isLoginPage) {
const url = request.nextUrl.clone();
url.pathname = '/login';
return NextResponse.redirect(url);
}
return NextResponse.next();
}
export const config = {
matcher: ['/dashboard/:path*', '/profile', '/settings'],
};
Server-Side Data Checks
While middleware protects routes, you also need to protect the data itself. A user might bypass client-side checks or try to access data via an API.
Always perform authorization checks directly within your Server Components, Server Actions, or API routes before fetching or mutating sensitive data.
- Middleware: Route-level access control.
- Server Components/Actions: Data-level access control.
Protecting Data in Server Components
Inside a Server Component, you can check the user's authentication status and roles to decide what data to fetch or display.
If the user isn't authorized, you might redirect them, show an 'Access Denied' message, or simply not render sensitive parts of the UI.
import { redirect } from 'next/navigation';
// Assume 'getUserSession' is a helper function
// that retrieves the current user's session from cookies/headers.
async function getUserSession() {
// In a real app, this would securely fetch session details.
// For demo, let's simulate a check.
const hasSessionCookie = true; // Check request headers for auth cookie
return hasSessionCookie ? { id: 'user123', name: 'Alice' } : null;
}
export default async function ProtectedDashboard() {
const user = await getUserSession();
if (!user) {
redirect('/login'); // Use next/navigation's redirect for Server Components
}
return (
<div>
<h1>Welcome, {user.name}!</h1>
<p>This is your confidential dashboard content.</p>
</div>
);
}
Protecting Data with Server Actions
Server Actions are powerful for handling form submissions and data mutations. It's critical to include authorization checks within them.
Before performing any database operations or sensitive logic, verify that the user initiating the action has the necessary permissions.
import { revalidatePath } from 'next/cache';
// Assume 'getCurrentUser' gets the user initiating the action
// and 'isAdmin' checks their role.
async function getCurrentUser() {
// Simulate fetching user from session/context
return { id: 'user123', role: 'admin' }; // Or 'guest'
}
async function createProduct(formData: FormData) {
'use server';
const user = await getCurrentUser();
if (!user || user.role !== 'admin') {
throw new Error('Unauthorized: Only admins can create products.');
}
const productName = formData.get('name') as string;
// Simulate database operation
console.log(`Admin ${user.id} created product: ${productName}`);
// await db.products.create({ data: { name: productName } });
revalidatePath('/admin/products');
return { success: true, message: 'Product created!' };
}
export default function ProductForm() {
return (
<form action={createProduct}>
<input type="text" name="name" placeholder="Product Name" required />
<button type="submit">Create Product</button>
</form>
);
}
Handling Access Denied
When a user is unauthorized, you need to provide clear feedback. This can be:
- Redirecting: To a login page or an 'Access Denied' page.
- Displaying an error: Showing a message directly on the page.
- Throwing an error: Allowing Next.js
error.jsboundaries to catch it.
Choose the method that best fits the user experience and the severity of the access attempt.
Defense in Depth
The best security approach is 'defense in depth'. This means applying multiple layers of security checks.
- Client-side: Hide UI elements (not for security, but UX).
- Middleware: Protect entire routes.
- Server Components/Actions: Protect specific data operations.
- Database: Use database-level permissions where appropriate.
Never trust client-side checks alone; always validate on the server.
Best Practices Summary
To ensure robust security for your Next.js application:
- Always Authenticate & Authorize: Verify user identity and permissions for every sensitive operation.
- Use Environment Variables: Store secrets (e.g., database credentials) securely.
- Sanitize Inputs: Prevent injection attacks by validating and sanitizing all user input.
- Least Privilege: Grant users only the minimum permissions they need.
Quick Check: Route Protection
You want to prevent unauthenticated users from accessing any page under /admin. Where should the primary check for this be implemented?
Recap: Protecting Your App
You've learned how to secure your Next.js 15 application using a multi-layered approach:
- Middleware: Guards entire routes, redirecting unauthorized users.
- Server Components: Conditionally render UI or redirect based on user authorization.
- Server Actions: Protect data mutations by verifying user permissions before execution.
Combining these techniques provides robust protection for both your routes and the sensitive data within your application.
Często zadawane pytania
Czy lekcja „Ochrona tras i danych” jest bezpłatna?
Tak — pełny tekst „Ochrona tras i danych” jest dostępny za darmo tutaj w sieci. Aby ćwiczyć ją interaktywnie (wbudowany edytor kodu i tutor AI dostępny 24/7) i odblokować resztę kursu Next.js 15 Fullstack (App Router + Server Actions), przejdź na CoddyKit PRO. Kurs Next.js 15 Fullstack (App Router + Server Actions) zawiera 6 lekcji w sumie.
Co nauczysz się w „Ochrona tras i danych”?
Zaimplementuj middleware i kontrole po stronie serwera, aby chronić wybrane trasy i dane na podstawie statusu uwierzytelnienia użytkownika Ćwiczysz Next.js 15 Fullstack (App Router + Server Actions) z praktycznym kodem, który uruchamiasz bezpośrednio w przeglądarce, a tutor AI dostępny 24/7 odpowiada na Twoje pytania podczas pracy nad lekcją.
Czy potrzebuję doświadczenia, aby zacząć Next.js 15 Fullstack (App Router + Server Actions)?
Nie wymagamy żadnego doświadczenia. Next.js 15 Fullstack (App Router + Server Actions) w CoddyKit jest strukturyzowany dla początkujących i zaawansowanych użytkowników, więc możesz zacząć tutaj lub od początku i uczyć się w swoim tempie. To lekcja 3 z 6.
Ile czasu zajmuje lekcja „Ochrona tras i danych”?
Większość lekcji CoddyKit trwa około 5–10 minut. Każda lekcja to mały, interaktywny krok, dzięki czemu robisz systematyczne postępy i zawsze wracasz dokładnie do tego samego miejsca — na webie i w aplikacji.
Czy mogę pisać i uruchamiać kod w tej lekcji Next.js 15 Fullstack (App Router + Server Actions)?
Tak. Każda lekcja Next.js 15 Fullstack (App Router + Server Actions) zawiera wbudowany edytor kodu, więc piszesz i uruchamiasz prawdziwy kod bezpośrednio w przeglądarce i od razu otrzymujesz sprzężenie zwrotne od AI — bez konfiguracji na komputerze.
Wszystkie lekcje w tym kursie
- Integracja NextAuth.js
- Implementacja strategii JWT
- Ochrona tras i danych
- Strażnicy i role
- Niestandardowe strategie uwierzytelniania
- Integracja Passport.js