Skip to content

test: check that server functions return no data without a session - #2

Closed
Mheaus wants to merge 1 commit into
feat/public-benchfrom
test/server-function-access
Closed

Mheaus wants to merge 1 commit into
feat/public-benchfrom
test/server-function-access

Conversation

@Mheaus

@Mheaus Mheaus commented Oct 9, 2026

Copy link
Copy Markdown
Member

Stacked on #1. Audit of NOTES P9: in React Router's RSC mode, a server function is an endpoint that a POST to any route can call; route middleware and loaders do not protect it.

Result

Each of Payload's 15 server functions was called on the production build, with and without a session, on an admin route, on the website home / and on a 404 route, with a draft page holding a secret.

  • Without a session, form-state and table-state are refused by Payload ("Unauthorized, you must be logged in"). switch-language runs by design (it sets the language cookie of the login page). The other 12 throw before they return data.
  • With a session, render-document, render-list, table-state and copy-data-from-locale return the draft from /, which proves the calls were well formed.
  • No call without a session returned data or wrote to the database.

Payload enforces this itself, function by function, as it must for Next.js server actions. No adapter change is needed. The table is in docs/COMPAT.md.

Test

New scenario 14-server-function-access: from /, the data functions must return the draft secret with the admin session and must not without one. Bench: 36/36 on the production build and on vite dev.

🤖 Generated with Claude Code

In React Router's RSC mode, a server function is an endpoint that a POST to any route can call; route middleware and loaders do not protect it (NOTES P9). Each of Payload's 15 server functions was called on the production build with and without a session, on an admin route, on / and on a 404 route. Without a session, form-state and table-state are refused by Payload, switch-language runs by design, and the others throw before they return data. No call wrote to the database.

The e2e scenario calls the data functions from / with the admin session, which must return a draft secret, and without a session, which must not. docs/COMPAT.md records the full table.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant