nextjs-authentication
maintained by HoangNguyen0403
star
143
account_tree
48
verified_user
MIT License
name: Next.js Authentication description: Secure token storage (HttpOnly Cookies) and Middleware patterns. metadata: labels: [nextjs, auth, security, cookies] triggers: files: ['middleware.ts', '/auth.ts', '/login/page.tsx'] keywords: [cookie, jwt, session, localstorage, auth]
Authentication & Token Management
Priority: P0 (CRITICAL)
Use HttpOnly Cookies for token storage. Never use LocalStorage.
Key Rules
-
Storage: Use
cookies().set()withhttpOnly: true,secure: true,sameSite: 'lax'. (Reference: Setting Tokens) -
Access: Read tokens in Server Components via
cookies().get(). (Reference: Reading Tokens) -
Protection: Guard routes in
middleware.tsbefore rendering. (Reference: Middleware Protection)
Anti-Pattern: LocalStorage
- Security Risk: Vulnerable to XSS.
- Performance Hit: Incompatible with Server Components (RSC). Forces client hydration and causes layout shift.
Related Topics
common/security-standards | server-components | app-router
chat Comments (0)
Sign in to join the discussion and leave a comment.
Skill Details
GitHub Stars
143
GitHub Forks
48
Created
Jan 2026
Last Updated
8 months ago
tools
tools security
Related Skills
Build your own?
Join 12,000+ developers contributing to the Claude ecosystem.
No comments yet. Be the first to share your thoughts!