Handling Authorization and Caching in Next.js: A Developer’s Guide

Next.js introduces powerful experimental features for access control and smart caching. This guide covers the unauthorized() function for custom 401 handling, unstable_cache for persistent memoization, updateTag for instant cache invalidation, and useLinkStatus for inline navigation feedback. Learn how to use these tools to build secure, performant, and responsive applications.

unauthorizedunstable_cacheupdateTaguseLinkStatus

~2 دقیقه مطالعه · آخرین به‌روزرسانی ۱۰ آبان ۱۴۰۴

1. Access Control with unauthorized()


unauthorized() throws a 401 error and renders the unauthorized.tsx page. It’s ideal for protecting sensitive routes and redirecting unauthenticated users to a login UI.


Enable in next.config.js:

experimental: {
  authInterrupts: true,
}

Example in Server Component:

const session = await verifySession()
if (!session) unauthorized()

Custom UI:

// app/unauthorized.tsx
<main>
  <h1>401 - Unauthorized</h1>
  <p>Please log in to access this page.</p>
  <Login />
</main>

2. Smart Caching with unstable_cache()


unstable_cache() memoizes expensive operations like database queries across requests and deployments.


Example:

const getCachedUser = unstable_cache(
  async (id) => fetchUser(id),
  ['user-cache-key'],
  { tags: ['users'], revalidate: 60 }
)

Tips:

  • Avoid accessing cookies or headers inside cached functions
  • Use tags for targeted invalidation
  • Use revalidate to set cache duration

3. Real-Time Invalidation with updateTag()


updateTag() expires cached data instantly after a mutation. It’s only available in Server Actions.


Example:

'use server'
import { updateTag } from 'next/cache'

export async function createPost(formData) {
  const post = await db.post.create({ data: formData })
  updateTag('posts')
  updateTag(`post-${post.id}`)
  redirect(`/posts/${post.id}`)
}

4. Opting Out of Caching with unstable_noStore()


unstable_noStore() disables caching and forces dynamic rendering.


Example:

import { unstable_noStore as noStore } from 'next/cache'

export default async function Component() {
  noStore()
  const data = await db.query(...)
}

5. Preserving Error Behavior with unstable_rethrow()


Use unstable_rethrow() to preserve Next.js error handling when catching errors like notFound() or redirect().


Example:

try {
  const res = await fetch(...)
  if (res.status === 404) notFound()
} catch (err) {
  unstable_rethrow(err)
}

6. Navigation Feedback with useLinkStatus()


useLinkStatus() tracks the pending state of a <Link> for subtle UI feedback during navigation.


Example:

'use client'
import { useLinkStatus } from 'next/link'

function Hint() {
  const { pending } = useLinkStatus()
  return <span className={`link-hint ${pending ? 'is-pending' : ''}`} />
}

Best Practices:

  • Use with prefetch={false}
  • Avoid layout shifts by animating opacity
  • Use route-level fallbacks with loading.js

Conclusion


With unauthorized() for access control, unstable_cache() for smart caching, updateTag() for real-time invalidation, and useLinkStatus() for smooth navigation, you can build secure, performant, and dynamic applications in Next.js.


نوشته و پژوهش‌شده توسط دکتر شاهین صیامی

مقالات مرتبط

Advanced Client-Side Routing and Performance Hooks in Next.js

Next.js provides a rich set of client-side hooks and caching utilities that empower developers to build dynamic, responsive, and secure applications. From reading route parameters to tracking navigation state and reporting performance metrics, this guide walks you through the most important tools available in the App Router.

ادامه

redirect and refresh in Next.js — Smart Redirects and Client Refreshing via Server Actions

The redirect function in Next.js allows you to navigate users to a new route, returning either a 307 or 303 HTTP response depending on context. It works in Server Components, Client Components, Route Handlers, and Server Actions. The refresh function is used exclusively within Server Actions to refresh the client router. This article explains how both functions work, with practical examples and key considerations.

ادامه

NextRequest and NextResponse in Next.js — Managing Cookies, Headers, Redirects, and Rewrites

Next.js extends the native Web Request and Response APIs with NextRequest and NextResponse, offering powerful tools for managing cookies, headers, redirects, rewrites, and JSON responses. These utilities simplify server-side logic and improve control over routing, personalization, and security. This guide walks through their capabilities with practical examples and best practices.

ادامه

headers, ImageResponse, notFound, and permanentRedirect in Next.js — Request Handling, Dynamic Images, Errors, and Redirects

Next.js offers powerful tools for handling HTTP requests and responses in Server Components. The headers function lets you read incoming request headers. ImageResponse allows you to generate dynamic images using JSX and CSS. The notFound function renders a custom 404 page, and permanentRedirect enables permanent redirection to another route. This article explains how to use each feature with practical examples.

ادامه

A Complete Guide to Using metadata and generateMetadata in Next.js

In modern versions of Next.js, managing page metadata is more powerful and intuitive than ever. Metadata is automatically injected into the <head> of your pages and plays a vital role in SEO, social sharing, and user experience. This guide explains the two main ways to define metadata: using the static metadata object and the dynamic generateMetadata function.

ادامه

generateStaticParams in Next.js — Prebuilding Dynamic Routes at Build Time

The generateStaticParams function in Next.js allows you to prebuild dynamic routes at build time instead of rendering them on-demand. It replaces getStaticPaths from the Pages Router and supports single, multiple, and catch-all segments. You can generate routes from the bottom up or top down, and control fallback behavior using dynamicParams. This article explains how to use generateStaticParams with practical examples and configuration tips.

ادامه