nextjs-authentication | Skill Performance & Reviews | TopRankSkills

TopRank Skills

Home / Skills / tools / nextjs-authentication

nextjs-authentication

maintained by HoangNguyen0403

star 143 account_tree 48 verified_user MIT License
bolt View GitHub

name: Next.js Authentication description: Secure token storage (HttpOnly Cookies) and Middleware patterns. metadata: labels: [nextjs, auth, security, cookies] triggers: files: ['middleware.ts', '/auth.ts', '/login/page.tsx'] keywords: [cookie, jwt, session, localstorage, auth]

Authentication & Token Management

Priority: P0 (CRITICAL)

Use HttpOnly Cookies for token storage. Never use LocalStorage.

Key Rules

  1. Storage: Use cookies().set() with httpOnly: true, secure: true, sameSite: 'lax'. (Reference: Setting Tokens)
  2. Access: Read tokens in Server Components via cookies().get(). (Reference: Reading Tokens)
  3. Protection: Guard routes in middleware.ts before rendering. (Reference: Middleware Protection)

Anti-Pattern: LocalStorage

  • Security Risk: Vulnerable to XSS.
  • Performance Hit: Incompatible with Server Components (RSC). Forces client hydration and causes layout shift.

Related Topics

common/security-standards | server-components | app-router

chat Comments (0)

chat_bubble_outline

No comments yet. Be the first to share your thoughts!

Skill Details

GitHub Stars 143
GitHub Forks 48
Created Jan 2026
Last Updated 8个月前
tools tools security

Related Skills

waf-bypass-hunter
chevron_right
permissions
chevron_right
auth
chevron_right
safety-check
chevron_right
clerk
chevron_right

Build your own?

Join 12,000+ developers contributing to the Claude ecosystem.