Authentication and authorization
Authorize on the server. A hidden button is not a permission.
Written for a Next.js 15 App Router application. Guidance for Next.js 16 bundled docs or /_next/mcp does not apply to 15.5.27.
Next.js authentication guideWhat this describes
Rules
A hidden button or a client redirect is not permission.
A session cookie is not readable from client JavaScript.
Do not ship Admin and Employee as if they were an approved CSC role model.
A sign-in form needs a server limit. The limit is not a disabled button alone.
const session = await readSession();
if (!session?.canApprove) return { error: 'Not allowed' };if (!showApproveButton) return null;
await approveRecord(id);The check is only in the interface. The operation still runs for anyone who calls it.
Checklist
- The mutation checks permission on the server.
- The session cookie is httpOnly.
- Examples use synthetic people, not real records.
AI instructions
You are implementing this practice in the current project. Do not install a design-system package and do not import one.
TASK: Apply Authentication and authorization.
Authorize on the server. A hidden button is not a permission.
APPLIES TO: Written for a Next.js 15 App Router application. Guidance for Next.js 16 bundled docs or /_next/mcp does not apply to 15.5.27.
RULES:
- NX-AUTH-001 [required] Authorize on the server. A hidden button or a client redirect is not permission.
- NX-AUTH-002 [required] Keep session cookies httpOnly. A session cookie is not readable from client JavaScript.
- NX-AUTH-003 [prohibited] Do not invent an official role list. Do not ship Admin and Employee as if they were an approved CSC role model.
- NX-AUTH-004 [recommended] Limit repeated sign-in attempts. A sign-in form needs a server limit. The limit is not a disabled button alone.
CORRECT:
const session = await readSession();
if (!session?.canApprove) return { error: 'Not allowed' };
INCORRECT:
if (!showApproveButton) return null;
await approveRecord(id);
The check is only in the interface. The operation still runs for anyone who calls it.
CHECK:
- [ ] The mutation checks permission on the server.
- [ ] The session cookie is httpOnly.
- [ ] Examples use synthetic people, not real records.
SOURCE: Next.js authentication guide https://nextjs.org/docs/app/guides/authentication
Build the interface with the project’s own markup. Match the documented colors and elements when a control is involved.
Do not upgrade Next.js to obtain bundled docs. Do not claim a WCAG audit. Do not add secrets.