NextRequest and NextResponse in Next.js — Managing Cookies, Headers, Redirects, and Rewrites

Next.js extends the native Web Request and Response APIs with NextRequest and NextResponse, offering powerful tools for managing cookies, headers, redirects, rewrites, and JSON responses. These utilities simplify server-side logic and improve control over routing, personalization, and security. This guide walks through their capabilities with practical examples and best practices.

NextRequestNextResponsecookiesredirectheaders

~2 دقیقه مطالعه · آخرین به‌روزرسانی ۱۰ آبان ۱۴۰۴

1. What Is NextRequest?


NextRequest extends the Web Request API with Next.js-specific methods for reading and mutating cookies and accessing enhanced URL properties.


Cookie Methods:

  • set(name, value): Set a cookie on the request
  • get(name): Get a cookie value
  • getAll(name?): Get all cookies or all with a specific name
  • delete(name): Remove a cookie
  • has(name): Check if a cookie exists
  • clear(): Remove all cookies from the request

URL Properties:

  • nextUrl.pathname: Get the request path
  • nextUrl.searchParams: Access query parameters
  • basePath, buildId: App-specific metadata

2. What Is NextResponse?


NextResponse extends the Web Response API with methods for setting cookies, returning JSON, redirecting, rewriting, and forwarding headers.


Cookie Methods:

  • set(name, value): Set a cookie on the response
  • get(name): Get a cookie value
  • getAll(name?): Get all cookies or all with a specific name
  • delete(name): Remove a cookie

Response Utilities:

  • json(data, options): Return a JSON response
  • redirect(url): Redirect to another URL
  • rewrite(url): Proxy a request while preserving the original URL
  • next(): Continue routing (useful for middleware and proxies)

3. Forwarding Headers Safely


When using NextResponse.next() to forward headers upstream, avoid copying all headers. Instead, use an allow-list to forward only safe headers:

const incoming = new Headers(request.headers)
const forwarded = new Headers()

for (const [name, value] of incoming) {
  const headerName = name.toLowerCase()
  if (
    !headerName.startsWith('x-') &&
    headerName !== 'authorization' &&
    headerName !== 'cookie'
  ) {
    forwarded.set(name, value)
  }
}

return NextResponse.next({ request: { headers: forwarded } })

4. Redirecting with Context


You can modify the redirect URL using request.nextUrl before calling NextResponse.redirect():

const loginUrl = new URL('/login', request.url)
loginUrl.searchParams.set('from', request.nextUrl.pathname)
return NextResponse.redirect(loginUrl)

5. Rewriting Requests


Use NextResponse.rewrite() to proxy a request while keeping the original URL visible in the browser:

return NextResponse.rewrite(new URL('/proxy', request.url))

Conclusion


NextRequest and NextResponse give you fine-grained control over cookies, headers, routing, and response behavior in Next.js. Use them to personalize user experiences, secure data flow, and optimize server-side logic.


نوشته و پژوهش‌شده توسط دکتر شاهین صیامی

مقالات مرتبط

Advanced Client-Side Routing and Performance Hooks in Next.js

Next.js provides a rich set of client-side hooks and caching utilities that empower developers to build dynamic, responsive, and secure applications. From reading route parameters to tracking navigation state and reporting performance metrics, this guide walks you through the most important tools available in the App Router.

ادامه

Handling Authorization and Caching in Next.js: A Developer’s Guide

Next.js introduces powerful experimental features for access control and smart caching. This guide covers the unauthorized() function for custom 401 handling, unstable_cache for persistent memoization, updateTag for instant cache invalidation, and useLinkStatus for inline navigation feedback. Learn how to use these tools to build secure, performant, and responsive applications.

ادامه

redirect and refresh in Next.js — Smart Redirects and Client Refreshing via Server Actions

The redirect function in Next.js allows you to navigate users to a new route, returning either a 307 or 303 HTTP response depending on context. It works in Server Components, Client Components, Route Handlers, and Server Actions. The refresh function is used exclusively within Server Actions to refresh the client router. This article explains how both functions work, with practical examples and key considerations.

ادامه

headers, ImageResponse, notFound, and permanentRedirect in Next.js — Request Handling, Dynamic Images, Errors, and Redirects

Next.js offers powerful tools for handling HTTP requests and responses in Server Components. The headers function lets you read incoming request headers. ImageResponse allows you to generate dynamic images using JSX and CSS. The notFound function renders a custom 404 page, and permanentRedirect enables permanent redirection to another route. This article explains how to use each feature with practical examples.

ادامه

A Complete Guide to Using metadata and generateMetadata in Next.js

In modern versions of Next.js, managing page metadata is more powerful and intuitive than ever. Metadata is automatically injected into the <head> of your pages and plays a vital role in SEO, social sharing, and user experience. This guide explains the two main ways to define metadata: using the static metadata object and the dynamic generateMetadata function.

ادامه

generateStaticParams in Next.js — Prebuilding Dynamic Routes at Build Time

The generateStaticParams function in Next.js allows you to prebuild dynamic routes at build time instead of rendering them on-demand. It replaces getStaticPaths from the Pages Router and supports single, multiple, and catch-all segments. You can generate routes from the bottom up or top down, and control fallback behavior using dynamicParams. This article explains how to use generateStaticParams with practical examples and configuration tips.

ادامه