├── .eslintrc.json ├── .gitignore ├── README.md ├── next-auth.d.ts ├── next.config.js ├── package-lock.json ├── package.json ├── postcss.config.js ├── public ├── next.svg └── vercel.svg ├── src ├── app │ ├── api │ │ └── auth │ │ │ └── [...nextauth] │ │ │ ├── options.ts │ │ │ └── route.ts │ ├── client │ │ └── page.tsx │ ├── components │ │ ├── Navbar.tsx │ │ └── UserCard.tsx │ ├── context │ │ └── AuthProvider.tsx │ ├── denied │ │ └── page.tsx │ ├── extra │ │ └── page.tsx │ ├── favicon.ico │ ├── globals.css │ ├── layout.tsx │ ├── page.tsx │ └── server │ │ └── page.tsx └── middleware.ts ├── tailwind.config.js └── tsconfig.json /.eslintrc.json: -------------------------------------------------------------------------------- 1 | { 2 | "extends": "next/core-web-vitals" 3 | } 4 | -------------------------------------------------------------------------------- /.gitignore: -------------------------------------------------------------------------------- 1 | # See https://help.github.com/articles/ignoring-files/ for more about ignoring files. 2 | 3 | # dependencies 4 | /node_modules 5 | /.pnp 6 | .pnp.js 7 | 8 | # testing 9 | /coverage 10 | 11 | # next.js 12 | /.next/ 13 | /out/ 14 | 15 | # production 16 | /build 17 | 18 | # misc 19 | .DS_Store 20 | *.pem 21 | 22 | # debug 23 | npm-debug.log* 24 | yarn-debug.log* 25 | yarn-error.log* 26 | 27 | # local env files 28 | .env*.local 29 | 30 | # vercel 31 | .vercel 32 | 33 | # typescript 34 | *.tsbuildinfo 35 | next-env.d.ts 36 | -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 | # "NextAuth.js Role-Based Access Control" 2 | 3 | ## User Authorization & Protected Routes 4 | 5 | ### With Next.js App Router 6 | 7 | --- 8 | 9 | ### Author Links 10 | 11 | 👋 Hello, I'm Dave Gray. 12 | 13 | 👉 [My Courses](https://courses.davegray.codes/) 14 | 15 | ✅ [Check out my YouTube Channel with hundreds of tutorials](https://www.youtube.com/DaveGrayTeachesCode). 16 | 17 | 🚩 [Subscribe to my channel](https://bit.ly/3nGHmNn) 18 | 19 | ☕ [Buy Me A Coffee](https://buymeacoffee.com/DaveGray) 20 | 21 | 🚀 Follow Me: 22 | 23 | - [Twitter](https://twitter.com/yesdavidgray) 24 | - [LinkedIn](https://www.linkedin.com/in/davidagray/) 25 | - [Blog](https://yesdavidgray.com) 26 | - [Reddit](https://www.reddit.com/user/DaveOnEleven) 27 | 28 | --- 29 | 30 | ### Description 31 | 32 | 📺 [YouTube Video](https://youtu.be/ay-atEUGIc4) for this repository. 33 | 34 | --- 35 | 36 | ### 🎓 Academic Honesty 37 | 38 | **DO NOT COPY FOR AN ASSIGNMENT** - Avoid plagiarism and adhere to the spirit of this [Academic Honesty Policy](https://www.freecodecamp.org/news/academic-honesty-policy/). 39 | 40 | --- 41 | 42 | ### ⚙ Free Web Dev Tools 43 | - 🔗 [Google Chrome Web Browser](https://google.com/chrome/) 44 | - 🔗 [Visual Studio Code (aka VS Code)](https://code.visualstudio.com/) 45 | - 🔗 [ES7 React Snippets](https://marketplace.visualstudio.com/items?itemName=dsznajder.es7-react-js-snippets) 46 | 47 | ### 📚 References 48 | - 🔗 [NextAuth.js Official Site](https://next-auth.js.org/) 49 | - 🔗 [Next.js Official Site](https://nextjs.org/) 50 | - 🔗 [NextAuth.js - Advanced Middleware Configuration](https://next-auth.js.org/configuration/nextjs#advanced-usage) 51 | - 🔗 [NextAuth.js - Persisting the Role](https://authjs.dev/guides/basics/role-based-access-control#persisting-the-role) 52 | - 🔗 [NextAuth.js - TypeScript Module Augmentation](https://next-auth.js.org/getting-started/typescript#module-augmentation 53 | ) 54 | - 🔗 [NextAuth.js - JWT & Session Callbacks](https://next-auth.js.org/configuration/callbacks#jwt-callback) 55 | - 🔗 [Next.js Rewrites](https://nextjs.org/docs/app/api-reference/functions/next-response#rewrite) 56 | 57 | 58 | -------------------------------------------------------------------------------- /next-auth.d.ts: -------------------------------------------------------------------------------- 1 | // Ref: https://next-auth.js.org/getting-started/typescript#module-augmentation 2 | 3 | import { DefaultSession, DefaultUser } from "next-auth" 4 | import { JWT, DefaultJWT } from "next-auth/jwt" 5 | 6 | declare module "next-auth" { 7 | interface Session { 8 | user: { 9 | id: string, 10 | role: string, 11 | } & DefaultSession 12 | } 13 | 14 | interface User extends DefaultUser { 15 | role: string, 16 | } 17 | } 18 | 19 | declare module "next-auth/jwt" { 20 | interface JWT extends DefaultJWT { 21 | role: string, 22 | } 23 | } -------------------------------------------------------------------------------- /next.config.js: -------------------------------------------------------------------------------- 1 | /** @type {import('next').NextConfig} */ 2 | const nextConfig = { 3 | images: { 4 | remotePatterns: [ 5 | { 6 | protocol: 'https', 7 | hostname: 'avatars.githubusercontent.com', 8 | port: '', 9 | pathname: '/u/**', 10 | }, 11 | ], 12 | }, 13 | } 14 | 15 | module.exports = nextConfig 16 | -------------------------------------------------------------------------------- /package.json: -------------------------------------------------------------------------------- 1 | { 2 | "name": "next-auth-rbac", 3 | "version": "0.1.0", 4 | "private": true, 5 | "scripts": { 6 | "dev": "next dev", 7 | "build": "next build", 8 | "start": "next start", 9 | "lint": "next lint" 10 | }, 11 | "dependencies": { 12 | "@types/node": "20.3.2", 13 | "@types/react": "18.2.14", 14 | "@types/react-dom": "18.2.6", 15 | "autoprefixer": "10.4.14", 16 | "eslint": "8.43.0", 17 | "eslint-config-next": "13.4.7", 18 | "next": "13.4.7", 19 | "next-auth": "^4.22.1", 20 | "postcss": "8.4.24", 21 | "react": "18.2.0", 22 | "react-dom": "18.2.0", 23 | "tailwindcss": "3.3.2", 24 | "typescript": "5.1.6" 25 | } 26 | } -------------------------------------------------------------------------------- /postcss.config.js: -------------------------------------------------------------------------------- 1 | module.exports = { 2 | plugins: { 3 | tailwindcss: {}, 4 | autoprefixer: {}, 5 | }, 6 | } 7 | -------------------------------------------------------------------------------- /public/next.svg: -------------------------------------------------------------------------------- 1 | -------------------------------------------------------------------------------- /public/vercel.svg: -------------------------------------------------------------------------------- 1 | -------------------------------------------------------------------------------- /src/app/api/auth/[...nextauth]/options.ts: -------------------------------------------------------------------------------- 1 | import type { NextAuthOptions } from 'next-auth' 2 | import GitHubProvider from 'next-auth/providers/github' 3 | import CredentialsProvider from 'next-auth/providers/credentials' 4 | import { GithubProfile } from 'next-auth/providers/github' 5 | 6 | export const options: NextAuthOptions = { 7 | providers: [ 8 | GitHubProvider({ 9 | profile(profile: GithubProfile) { 10 | //console.log(profile) 11 | return { 12 | ...profile, 13 | role: profile.role ?? "user", 14 | id: profile.id.toString(), 15 | image: profile.avatar_url, 16 | } 17 | }, 18 | clientId: process.env.GITHUB_ID as string, 19 | clientSecret: process.env.GITHUB_SECRET as string, 20 | }), 21 | CredentialsProvider({ 22 | name: "Credentials", 23 | credentials: { 24 | username: { 25 | label: "Username:", 26 | type: "text", 27 | placeholder: "your-cool-username" 28 | }, 29 | password: { 30 | label: "Password:", 31 | type: "password", 32 | placeholder: "your-awesome-password" 33 | } 34 | }, 35 | async authorize(credentials) { 36 | // This is where you need to retrieve user data 37 | // to verify with credentials 38 | // Docs: https://next-auth.js.org/configuration/providers/credentials 39 | const user = { id: "42", name: "Dave", password: "nextauth", role: "manager" } 40 | 41 | if (credentials?.username === user.name && credentials?.password === user.password) { 42 | return user 43 | } else { 44 | return null 45 | } 46 | } 47 | }) 48 | ], 49 | callbacks: { 50 | // Ref: https://authjs.dev/guides/basics/role-based-access-control#persisting-the-role 51 | async jwt({ token, user }) { 52 | if (user) token.role = user.role 53 | return token 54 | }, 55 | // If you want to use the role in client components 56 | async session({ session, token }) { 57 | if (session?.user) session.user.role = token.role 58 | return session 59 | }, 60 | } 61 | } -------------------------------------------------------------------------------- /src/app/api/auth/[...nextauth]/route.ts: -------------------------------------------------------------------------------- 1 | import NextAuth from 'next-auth' 2 | import { options } from './options' 3 | 4 | const handler = NextAuth(options) 5 | 6 | export { handler as GET, handler as POST } -------------------------------------------------------------------------------- /src/app/client/page.tsx: -------------------------------------------------------------------------------- 1 | 'use client' 2 | // Remember you must use an AuthProvider for 3 | // client components to useSession 4 | import { useSession } from 'next-auth/react' 5 | import { redirect } from 'next/navigation' 6 | import UserCard from '../components/UserCard' 7 | 8 | export default function ClientPage() { 9 | const { data: session } = useSession({ 10 | required: true, 11 | onUnauthenticated() { 12 | redirect('/api/auth/signin?callbackUrl=/client') 13 | } 14 | }) 15 | 16 | // if (session?.user.role !== "admin" 17 | // && session?.user.role !== "manager") { 18 | // return
{pagetype} Page!
42 |Role: {user?.role}
43 |You are logged in, but you do not have the 8 | required access level to view this page. 9 |
10 | Return to Home Page 11 |