Nextjs authentication
Skill ComeOnOliver/skillshub/skills/HoangNguyen0403/agent-skills-standard/nextjs-authentication
🧠The right skill, one API call. AI agent skills registry with token-efficient skill resolution. 5,000+ skills from 500+ top repos.
npx -y skills add ComeOnOliver/skillshub --skill nextjs-authenticationAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
What its author says it does
Copied from the file, not written here
Secure token storage (HttpOnly Cookies) and Middleware patterns. Use when implementing authentication, secure session storage, or auth middleware in Next.js. (triggers: middleware.ts, **/auth.ts, **/login/page.tsx, cookie, jwt, session, localstorage, auth)
SKILL.md
2.1 KB, as published. Nobody here has run it
Authentication & Token Management
Priority: P0 (CRITICAL)
Use HttpOnly Cookies for token storage. Never use LocalStorage or sessionStorage.
Implementation Guidelines
- Token Storage: Strictly use
HttpOnly,Securecookies withSameSite: 'Lax'or'Strict'. Set reasonablemaxAge(e.g., 86400). Never store access tokens inlocalStorageorsessionStorage(XSS-vulnerable). LocalStorage causes hydration issues in Server Components. - Access Management: Read and verify tokens in Next.js Middleware (
middleware.ts) for edge-side redirection and route protection. UseNextRequestto get cookies andNextResponse.redirectfor unauthorized users. Usematcherin config for route protection. - Next.js 15+ Async: Remember that
cookies()is a Promise fromnext/headersand must be awaited:const cookieStore = await cookies();. Access values via(await cookies()).get('token')?.value. Never pass raw token to Client Components. - Library Selection: Prefer
next-auth(Auth.js) or Clerck for social logins and session management. Reach forgetServerSessionorauth()(Auth.js) to read an encrypted session. - Data Access: Always use a
DAL(Data Access Layer) to validate credentials and verifies cookie presence before rendering. - CSRF Protection: Guard all Server Actions and Route Handlers by verifying the Origin/Referer headers.
- User Verification: Use
await auth()(from Auth.js) or a customgetSession()helper in Server Components. Always validate the session on the backend even if requested via Client Component.