Treating actions as public endpoints.
01
01
Understand the problem
nextjsserver-actionssecurityvalidation
02
02
Attempt it yourself
Sketch your approach before reading the solution — that's what interviews test.
Stuck? AI Nudge Available
Get a conceptual hint to guide your logic without spoiling the final implementation.
03
03
Study the solution
The solution is waiting
Give it an honest attempt first — then compare your thinking with the full walkthrough.
04
04
Read the code
A hardened Server Action
'use server';
import { z } from 'zod';
import { auth } from '@/lib/auth';
const Schema = z.object({ postId: z.string().uuid() });
export async function deletePost(input: unknown) {
const session = await auth();
if (!session) throw new Error('unauthenticated'); // authn
const { postId } = Schema.parse(input); // validate
const post = await db.post.find(postId);
if (post.authorId !== session.user.id) throw new Error('forbidden'); // authz
await db.post.delete(postId);
}05
05
Join the discussion
Discussion (0)
Sign in to join the discussion.
No responses yet. Be the first to share what you think.