Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

Next.js security tip: Use "server only" for the code that should never be exposed to the client.

109,311 Aufrufe • vor 1 Jahr •via X (Twitter)

10 Kommentare

Profilbild von Andric
Andricvor 1 Jahr

Never understood why server only is a package and not a directive.

Profilbild von Matija Marohnić 🦋
Matija Marohnić 🦋vor 1 Jahr

This is really good, it's surprising that among all of talk about security concerns about RSCs and Server Actions in Next.js I've never heard about this.

Profilbild von Alex Sidorenko
Alex Sidorenkovor 1 Jahr

Here is a great in-depth article about security in Next.js

Profilbild von Vance Lucas
Vance Lucasvor 1 Jahr

The fact that it is even possible to accidentally ship sensitive server code to the client is a huge red flag. 🚩🚩🚩

Profilbild von Windfan
Windfanvor 1 Jahr

it's very easy to get confused by "use server" and `import "server-only"`. Now I have 3 different function files to help me, post.server.ts(using server-only), post.action.ts(using "use server") and post.ts(the functions that can be called by server or client components)

Profilbild von Phong
Phongvor 1 Jahr

in a few years I swear we are going to go full circle again back to client server separation as the latest fad

Profilbild von Terry Carson
Terry Carsonvor 1 Jahr

Nice one...thanks

Profilbild von Prasenjit
Prasenjitvor 1 Jahr

That's a crucial tip! Keeping sensitive code on the server side is essential for protecting your application. It helps ensure that no confidential data is exposed to users. Thanks for sharing this important reminder!

Profilbild von Artur
Arturvor 1 Jahr

We need "use security" directive ASAP😁

Profilbild von fulco
fulcovor 1 Jahr

Wish this was a directory like with sveltekit

Ähnliche Videos