Registry / web-framework / nextjs-basic-auth

nextjs-basic-auth

JSON →
library0.1.3jsnpmunverified

nextjs-basic-auth provides a straightforward method for integrating HTTP Basic Authentication directly into Next.js applications on a per-route basis. Currently at version 0.1.3, this package is designed for simplicity, offering an `initializeBasicAuth` function that returns a check function to be awaited within `getServerSideProps`. It explicitly requires developers to opt out of Next.js's static generation for any authenticated pages, as it needs a server-side context to perform credential checks for each request. Its release cadence appears stable and infrequent, focusing on a specific, well-defined security concern for Next.js page routes. Key differentiators include its direct integration with `getServerSideProps` for page-level protection, in contrast to middleware-based solutions (like `nextjs-basic-auth-middleware`) or more comprehensive authentication libraries (like NextAuth.js) that handle broader authentication flows including sessions, OAuth, and database integration.

web-frameworkauth-security
Install & Compatibility
Where this runs
tested against v? · npm install
Install × environment matrix
Each cell = how many times install + import succeeded across repeated harness runs. Partial = flaky.
glibc = Debian/Ubuntu slim · musl = Alpine Linux
musl
node 18226 runs
build_error
glibc
node 18226 runs
build_error
Code
Verified usage

Verified import paths — ran on the pinned version, not inferred.

The package uses ES Modules by default. While Node.js can sometimes interop, explicit ESM import is preferred. CommonJS `require` might lead to issues or incorrect imports depending on project configuration.

import initializeBasicAuth from 'nextjs-basic-auth'

Demonstrates initializing basic authentication with a list of users and applying it to a Next.js page using `getServerSideProps` to protect the route.

import initializeBasicAuth from 'nextjs-basic-auth'; const users = [ { user: 'user1', password: 'toocool' }, { user: 'admin', password: process.env.ADMIN_PASSWORD ?? 'password' }, // Use env vars for production! ]; // Initialize the basic auth checker once globally or per module const basicAuthCheck = initializeBasicAuth({ users: users }); // In your Next.js page file (e.g., pages/protected.js or app/protected/page.js for Pages Router or App Router with getServerSideProps emulation) export async function getServerSideProps(ctx) { const { req, res } = ctx; // Await the auth check. If authentication fails, it will send a 401 response and prompt the user. await basicAuthCheck(req, res); // If authentication passes, proceed with rendering the page return { props: {}, }; } // If using the App Router, this pattern is less direct and would typically involve server components or middleware. // This example is primarily for the Pages Router where getServerSideProps is common.
Debug
Known footguns
breakingThis package is designed for the Next.js Pages Router and relies on `getServerSideProps`. It does not directly support the new App Router's server components or middleware architecture in the same way. Adapting it for the App Router would require significant manual changes or a different approach.
gotchaProtecting a route with `nextjs-basic-auth` requires that the page opts out of Next.js's Static Site Generation (SSG). Pages using this library *must* use `getServerSideProps` or a similar server-side rendering mechanism, as the authentication check needs access to the `req` and `res` objects at runtime.
gotchaStoring sensitive credentials like user passwords directly in source code, even if hashed, is a security risk. The `users` array should ideally be populated from secure environment variables or a database, especially for production environments.
deprecatedThe package has not seen updates in over 5 years. While it may still function for its specific use case, it does not leverage newer Next.js features like Middleware for authentication, which is generally a more recommended approach for global or group-based route protection in modern Next.js applications.
Upgrade
Version history

Breaking-change detection hasn't run for this library yet.

Audit
Security & dependencies

CVE tracking and dependency tree are planned for a later release.

Agent activity
9 hits · last 30 days
gptbot
4
ahrefsbot
4
script
1
Resources