Repository navigation
Conversation
In React Router's RSC mode, a server function is an endpoint that a POST to any route can call; route middleware and loaders do not protect it (NOTES P9). Each of Payload's 15 server functions was called on the production build with and without a session, on an admin route, on / and on a 404 route. Without a session, form-state and table-state are refused by Payload, switch-language runs by design, and the others throw before they return data. No call wrote to the database. The e2e scenario calls the data functions from / with the admin session, which must return a draft secret, and without a session, which must not. docs/COMPAT.md records the full table.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #1. Audit of NOTES P9: in React Router's RSC mode, a server function is an endpoint that a POST to any route can call; route middleware and loaders do not protect it.
Result
Each of Payload's 15 server functions was called on the production build, with and without a session, on an admin route, on the website home
/and on a 404 route, with a draft page holding a secret.form-stateandtable-stateare refused by Payload ("Unauthorized, you must be logged in").switch-languageruns by design (it sets the language cookie of the login page). The other 12 throw before they return data.render-document,render-list,table-stateandcopy-data-from-localereturn the draft from/, which proves the calls were well formed.Payload enforces this itself, function by function, as it must for Next.js server actions. No adapter change is needed. The table is in
docs/COMPAT.md.Test
New scenario
14-server-function-access: from/, the data functions must return the draft secret with the admin session and must not without one. Bench: 36/36 on the production build and onvite dev.🤖 Generated with Claude Code