Loading video...

Video Failed to Load

Go Home

Next.js security tip: Use "server only" for the code that should never be exposed to the client.

109,311 views • 1 year ago •via X (Twitter)

10 Comments

Andric's profile picture
Andric1 year ago

Never understood why server only is a package and not a directive.

Matija Marohnić 🦋's profile picture
Matija Marohnić 🦋1 year ago

This is really good, it's surprising that among all of talk about security concerns about RSCs and Server Actions in Next.js I've never heard about this.

Alex Sidorenko's profile picture
Alex Sidorenko1 year ago

Here is a great in-depth article about security in Next.js

Vance Lucas's profile picture
Vance Lucas1 year ago

The fact that it is even possible to accidentally ship sensitive server code to the client is a huge red flag. 🚩🚩🚩

Windfan's profile picture
Windfan1 year ago

it's very easy to get confused by "use server" and `import "server-only"`. Now I have 3 different function files to help me, post.server.ts(using server-only), post.action.ts(using "use server") and post.ts(the functions that can be called by server or client components)

Phong's profile picture
Phong1 year ago

in a few years I swear we are going to go full circle again back to client server separation as the latest fad

Terry Carson's profile picture
Terry Carson1 year ago

Nice one...thanks

Prasenjit's profile picture
Prasenjit1 year ago

That's a crucial tip! Keeping sensitive code on the server side is essential for protecting your application. It helps ensure that no confidential data is exposed to users. Thanks for sharing this important reminder!

Artur's profile picture
Artur1 year ago

We need "use security" directive ASAP😁

fulco's profile picture
fulco1 year ago

Wish this was a directory like with sveltekit

Related Videos