knowledge-base
This file contains domain knowledge about the Cal.diy product and codebase. For coding…
**Impact: CRITICAL (Prevents unauthorized access to sensitive data)**
$ npx -y skills add calcom/cal.diy --agent claude-codeHow it fires
How this agent gets triggered: by you, by Claude, or both.
Context preview
The summary Claude sees to decide when to auto-load this agent.
**Impact: CRITICAL (Prevents unauthorized access to sensitive data)**
paths: - "apps/**/page.tsx" - "apps/**/layout.tsx" title: Page-Level Authorization Checks in Next.js impact: CRITICAL impactDescription: Prevents unauthorized access to sensitive data tags: security, nextjs, authorization, architecture
**Impact: CRITICAL (Prevents unauthorized access to sensitive data)**
Authorization checks must be performed in `page.tsx` or server components, never in `layout.tsx`. Layouts don't intercept all requests and can be bypassed.
**Incorrect (auth checks in layout):**
// app/admin/layout.tsx - DON'T DO THIS
export default async function AdminLayout({ children }) {
const session = await getUserSession();
if (!session?.user.role === "admin") {
redirect("/");
}
return <div>{children}</div>;
}**Correct (auth checks in page):**
// app/admin/page.tsx
import { redirect } from "next/navigation";
import { getUserSession } from "@/lib/auth";
export default async function AdminPage() {
const session = await getUserSession();
if (!session || session.user.role !== "admin") {
redirect("/"); // Or show an error
}
// Protected content here
return <div>Welcome, Admin!</div>;
}**Why layouts are unsafe for auth:**
**Key rules:**
Reference: [Next.js Security Best Practices](https://nextjs.org/docs/app/building-your-application/authentication)
Repo: calcom/cal.com
This file contains domain knowledge about the Cal.diy product and codebase. For coding…
The `packages/features` package should contain only framework-agnostic code: - Repositories…