Skip to content
Next.js Data Access Layer logo

Next.js Data Access Layer

Secure, reusable data access patterns with DTOs and Taint checks.

ngxtm/devkit0installs8starsSecurity

SKILL.md

Full skill instructions

Data Access Layer (DAL)

Priority: P1 (HIGH)

Centralize all data access (Database & External APIs) to ensure consistent security, authorization, and caching.

Principles

  1. Server-Only: Must include import 'server-only' to prevent Client bundling.
  2. Auth Co-location: Auth checks (session.role) must be inside the DAL function.
  3. DTO Transformation: Return plain objects (DTOs), never raw ORM instances.
  4. No Internal Fetch: Call DAL functions directly. Do not fetch('localhost/​api').

Implementation

ApproachWhen to useReference
API Gateway (BFF)Enterprise apps with separated Backend (NestJS).Pattern A
Direct DBFullstack apps or Admin Panels.Pattern B

Limitations

  • Client Components: Cannot import DAL files. Must use Server Actions or Route Handlers as bridges.