Treating actions as public endpoints.
Skip to solutionKEEP THE
hardFrontend
What are the security considerations for Server Actions in Next.js?
764 views
01
Understand the problem
nextjsserver-actionssecurityvalidation
02
Attempt it yourself
Sketch your approach before reading the solution — that's what interviews test.
Nudge consolestandby
Stuck? Beam a request up — the console returns a conceptual nudge that guides your logic without spoiling the implementation.
03
Study the solution
Server Actions are public HTTP endpoints, so you must authenticate/authorize inside each one, validate all inputs (zod), and never trust client-provided ids. Next.js adds protections (encrypted action ids, origin checks), but auth and validation are your responsibility.
Solution ready — 2 min read
Classified // press E to declassify
04
Read the code
A hardened Server Action
'use server';
import { z } from 'zod';
import { auth } from '@/lib/auth';
const Schema = z.object({ postId: z.string().uuid() });
export async function deletePost(input: unknown) {
const session = await auth();
if (!session) throw new Error('unauthenticated'); // authn
const { postId } = Schema.parse(input); // validate
const post = await db.post.find(postId);
if (post.authorId !== session.user.id) throw new Error('forbidden'); // authz
await db.post.delete(postId);
}05
Join the discussion
Discussion (0)
Sign in to join the discussion.
No responses yet. Be the first to share what you think.
Transmission complete // awaiting log
KEEP THE
STREAK ALIVE.
Dossier 83 of 95 decoded in the Next.js track. One more won't hurt.