All fixes

Require auth on an open API endpoint

broken-access

An API endpoint returns data with no authentication at all, so anyone who guesses the URL reads it. Put the check on the route, not on the UI.

Next.js

  1. 1 Add authentication checks to your API routes and middleware
typescript
// middleware.ts
export function middleware(request) {
  const session = getToken({ req: request });
  if (!session && request.nextUrl.pathname.startsWith('/api/')) {
    return new Response('Unauthorized', { status: 401 });
  }
}

Does your app still have this?

Scan your domain