Require auth on an open API endpoint
broken-access
An API endpoint returns data with no authentication at all, so anyone who guesses the URL reads it. Put the check on the route, not on the UI.
Frameworks
Next.js
- 1 Add authentication checks to your API routes and middleware
typescript
// middleware.ts
export function middleware(request) {
const session = getToken({ req: request });
if (!session && request.nextUrl.pathname.startsWith('/api/')) {
return new Response('Unauthorized', { status: 401 });
}
}Does your app still have this?
Scan your domain