architecture-page-level-auth
**Impact: CRITICAL (Prevents unauthorized access to sensitive data)**
$ npx -y skills add calcom/cal.com --agent claude-codeHow it fires
How this agent gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
Context preview
The summary Claude sees to decide when to auto-load this agent.
**Impact: CRITICAL (Prevents unauthorized access to sensitive data)**
Agent definition
architecture-page-level-auth.mdpaths:
- "apps/**/page.tsx"
- "apps/**/layout.tsx"
title: Page-Level Authorization Checks in Next.js
impact: CRITICAL
impactDescription: Prevents unauthorized access to sensitive data
tags: security, nextjs, authorization, architecture
Page-Level Authorization Checks in Next.js
**Impact: CRITICAL (Prevents unauthorized access to sensitive data)**
Authorization checks must be performed in `page.tsx` or server components, never in `layout.tsx`. Layouts don't intercept all requests and can be bypassed.
**Incorrect (auth checks in layout):**
// app/admin/layout.tsx - DON'T DO THIS
export default async function AdminLayout({ children }) {
const session = await getUserSession();
if (!session?.user.role === "admin") {
redirect("/");
}
return <div>{children}</div>;
}**Correct (auth checks in page):**
// app/admin/page.tsx
import { redirect } from "next/navigation";
import { getUserSession } from "@/lib/auth";
export default async function AdminPage() {
const session = await getUserSession();
if (!session || session.user.role !== "admin") {
redirect("/"); // Or show an error
}
// Protected content here
return <div>Welcome, Admin!</div>;
}**Why layouts are unsafe for auth:**
- Layouts don't intercept all requests (direct navigation, refreshes)
- APIs and server actions bypass layouts entirely
- Risk of data leaks if layout check is skipped
**Key rules:**
- Check permissions inside every restricted `page.tsx`
- Validate session/user/role before querying sensitive data
- Redirect or return nothing to unauthorized users before running restricted code
Reference: [Next.js Security Best Practices](https://nextjs.org/docs/app/building-your-application/authentication)
Read more
paths: - "apps/**/page.tsx" - "apps/**/layout.tsx" title: Page-Level Authorization Checks in Next.js impact: CRITICAL impactDescription: Prevents unauthorized access to sensitive data tags: security, nextjs, authorization, architecture
Page-Level Authorization Checks in Next.js
**Impact: CRITICAL (Prevents unauthorized access to sensitive data)**
Authorization checks must be performed in `page.tsx` or server components, never in `layout.tsx`. Layouts don't intercept all requests and can be bypassed.
**Incorrect (auth checks in layout):**
// app/admin/layout.tsx - DON'T DO THIS
export default async function AdminLayout({ children }) {
const session = await getUserSession();
if (!session?.user.role === "admin") {
redirect("/");
}
return <div>{children}</div>;
}**Correct (auth checks in page):**
// app/admin/page.tsx
import { redirect } from "next/navigation";
import { getUserSession } from "@/lib/auth";
export default async function AdminPage() {
const session = await getUserSession();
if (!session || session.user.role !== "admin") {
redirect("/"); // Or show an error
}
// Protected content here
return <div>Welcome, Admin!</div>;
}**Why layouts are unsafe for auth:**
- Layouts don't intercept all requests (direct navigation, refreshes)
- APIs and server actions bypass layouts entirely
- Risk of data leaks if layout check is skipped
**Key rules:**
- Check permissions inside every restricted `page.tsx`
- Validate session/user/role before querying sensitive data
- Redirect or return nothing to unauthorized users before running restricted code
Reference: [Next.js Security Best Practices](https://nextjs.org/docs/app/building-your-application/authentication)
Repo: calcom/cal.com
Other agents on caldiy.
- knowledge-base
This file contains domain knowledge about the Cal.diy product and codebase. For coding guidelines and rules, see [`rules/`](rules/).
Open agent - api-no-breaking-changes
**Impact: CRITICAL**
Open agent - api-thin-controllers
**Impact: HIGH**
Open agent - architecture-circular-dependencies
**Impact: CRITICAL**
Open agent - architecture-feature-boundaries
**Impact: CRITICAL**
Open agent - architecture-features-modules
The `packages/features` package should contain only framework-agnostic code: - Repositories (data access layer) - Services (business logic) - Core utilities and helpers - Types and interfaces
Open agent

