middleware-protection
Implement declarative security and route protection in Next.js applications.
Install
mkdir -p .claude/skills/middleware-protection && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/4274" && unzip -o skill.zip -d .claude/skills/middleware-protection && rm skill.zipInstalls to .claude/skills/middleware-protection
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Protect routes with Next.js middleware. Check authentication once, protect routes declaratively. Supports public routes, protected routes, and role-based access.Key capabilities
- →Centralize authentication checks for multiple routes
- →Implement role-based access control
- →Refresh user sessions during SSR
- →Inject user ID into request headers
- →Handle API-specific error responses
How it works
The middleware intercepts all requests to verify session validity via Supabase, then either redirects unauthenticated users or injects the user ID into headers for downstream routes.
Inputs & outputs
When to use middleware-protection
- →Protect private routes
- →Implement role-based access
- →Verify auth tokens on requests
About middleware-protection
Manages route-level security logic within Next.js middleware. Allows for centralized enforcement of public vs. protected routes and user roles.
Protect routes with Next.js middleware. Check authentication once, protect routes declaratively. Supports public routes, protected routes, and role-based access.
When not to use it
- →When using client-side only routing without server-side middleware
- →When authentication is handled entirely by a third-party service provider without custom route logic
Prerequisites
Limitations
- →Must explicitly skip static files and internal Next.js paths
- →Requires careful configuration to avoid redirect loops
How it compares
This approach centralizes security logic in one file rather than repeating authentication checks across every individual route handler.
Compared to similar skills
middleware-protection side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| middleware-protection (this skill) | 1 | 7mo | Review | Intermediate |
| auth-patterns | 7 | 9mo | Review | Intermediate |
| reviewing-nextjs-16-patterns | 11 | 10mo | Review | Intermediate |
| better-auth | 5 | 10mo | Review | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by dadbodgeoff
View all by dadbodgeoff →You might also like
auth-patterns
davepoon
This skill should be used when the user asks about "authentication in Next.js", "NextAuth", "Auth.js", "middleware auth", "protected routes", "session management", "JWT", "login flow", or needs guidance on implementing authentication and authorization in Next.js applications.
reviewing-nextjs-16-patterns
djankies
Review code for Next.js 16 compliance - security patterns, caching, breaking changes. Use when reviewing Next.js code, preparing for migration, or auditing for violations.
better-auth
mrgoonie
Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. Features include email/password authentication with verification, OAuth providers (Google, GitHub, Discord, etc.), two-factor authentication (TOTP, SMS), passkeys/WebAuthn support, session management, role-based access control (RBAC), rate limiting, and database adapters. Use when adding authentication to applications, implementing OAuth flows, setting up 2FA/MFA, managing user sessions, configuring authorization rules, or building secure authentication systems for web applications.
route-handlers
davepoon
This skill should be used when the user asks to "create an API route", "add an endpoint", "build a REST API", "handle POST requests", "create route handlers", "stream responses", or needs guidance on Next.js API development in the App Router.
nextjs-server-side-error-debugging
blader
Debug getServerSideProps and getStaticProps errors in Next.js. Use when: (1) Page shows generic error but browser console is empty, (2) API routes return 500 with no details, (3) Server-side code fails silently, (4) Error only occurs on refresh not client navigation. Check terminal/server logs instead of browser for actual error messages.
azure-keyvault-keys-ts
microsoft
Manage cryptographic keys using Azure Key Vault Keys SDK for JavaScript (@azure/keyvault-keys). Use when creating, encrypting/decrypting, signing, or rotating keys.