正在加载视频...

视频加载失败

Next.js security tip: Use "server only" for the code that should never be exposed to the client.

109,311 次观看 • 1 年前 •via X (Twitter)

10 条评论

Andric 的头像
Andric1 年前

Never understood why server only is a package and not a directive.

Matija Marohnić 🦋 的头像
Matija Marohnić 🦋1 年前

This is really good, it's surprising that among all of talk about security concerns about RSCs and Server Actions in Next.js I've never heard about this.

Alex Sidorenko 的头像
Alex Sidorenko1 年前

Here is a great in-depth article about security in Next.js

Vance Lucas 的头像
Vance Lucas1 年前

The fact that it is even possible to accidentally ship sensitive server code to the client is a huge red flag. 🚩🚩🚩

Windfan 的头像
Windfan1 年前

it's very easy to get confused by "use server" and `import "server-only"`. Now I have 3 different function files to help me, post.server.ts(using server-only), post.action.ts(using "use server") and post.ts(the functions that can be called by server or client components)

Phong 的头像
Phong1 年前

in a few years I swear we are going to go full circle again back to client server separation as the latest fad

Terry Carson 的头像
Terry Carson1 年前

Nice one...thanks

Prasenjit 的头像
Prasenjit1 年前

That's a crucial tip! Keeping sensitive code on the server side is essential for protecting your application. It helps ensure that no confidential data is exposed to users. Thanks for sharing this important reminder!

Artur 的头像
Artur1 年前

We need "use security" directive ASAP😁

fulco 的头像
fulco1 年前

Wish this was a directory like with sveltekit

相关视频