Skip to content
AI & Agents
Agent

architecture-page-level-auth

**Impact: CRITICAL (Prevents unauthorized access to sensitive data)**

From plugin
caldiy
47k95 skills95 agents
Install
$ npx -y skills add calcom/cal.com --agent claude-code

How it fires

How this agent gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.

Context preview

The summary Claude sees to decide when to auto-load this agent.

**Impact: CRITICAL (Prevents unauthorized access to sensitive data)**

Agent definition

architecture-page-level-auth.md
paths:
  - "apps/**/page.tsx"
  - "apps/**/layout.tsx"
title: Page-Level Authorization Checks in Next.js
impact: CRITICAL
impactDescription: Prevents unauthorized access to sensitive data
tags: security, nextjs, authorization, architecture

Page-Level Authorization Checks in Next.js

**Impact: CRITICAL (Prevents unauthorized access to sensitive data)**

Authorization checks must be performed in `page.tsx` or server components, never in `layout.tsx`. Layouts don't intercept all requests and can be bypassed.

**Incorrect (auth checks in layout):**

// app/admin/layout.tsx - DON'T DO THIS
export default async function AdminLayout({ children }) {
  const session = await getUserSession();
  if (!session?.user.role === "admin") {
    redirect("/");
  }
  return <div>{children}</div>;
}

**Correct (auth checks in page):**

// app/admin/page.tsx
import { redirect } from "next/navigation";
import { getUserSession } from "@/lib/auth";

export default async function AdminPage() {
  const session = await getUserSession();

  if (!session || session.user.role !== "admin") {
    redirect("/"); // Or show an error
  }

  // Protected content here
  return <div>Welcome, Admin!</div>;
}

**Why layouts are unsafe for auth:**

  • Layouts don't intercept all requests (direct navigation, refreshes)
  • APIs and server actions bypass layouts entirely
  • Risk of data leaks if layout check is skipped

**Key rules:**

  • Check permissions inside every restricted `page.tsx`
  • Validate session/user/role before querying sensitive data
  • Redirect or return nothing to unauthorized users before running restricted code

Reference: [Next.js Security Best Practices](https://nextjs.org/docs/app/building-your-application/authentication)

Read more
Ships withcaldiy

Scheduling infrastructure for absolutely everyone.

Get the whole plugin