本文へ移動
cccskills
無料GitHub で公開

api-routes-hardening

Use this skill when creating or reviewing Next.js Route Handlers (app/api), adding rate limiting, input validation, or auth to API endpoints. Trigger words: API ルート, Route Handler, app/api, エンドポイント, レート制限, 入力検証, CORS, ヘッダー, 認証付き API, hardening.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md2.3 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

API Routes 堅牢化

いつ使うか

  • app/api/**/route.ts(Route Handler)を作る/レビューするとき。
  • エンドポイントに認証・入力検証・レート制限を付けるとき。

やること

  • 入力(body/query/params)を Zod で検証してから処理する。
  • 認証/認可を冒頭でチェック(requireUser/requireAdmin)。
  • レート制限・サイズ上限を設ける(濫用・DoS 緩和)。
  • 返却は明示的な型・ステータスコード。内部エラーは漏らさない。
  • 動的データは適切なキャッシュ指定(revalidate と no-store を混在させない)。

守るルール

  • ✅ 入力 Zod 検証 + 認証/認可 + レート制限の 3 点セット。
  • ✅ エラー時はユーザー向け要約 + 内部ログ分離。
  • ✅ 適切な HTTP ステータス(400/401/403/404/429/500)を返す。
  • ❌ req.json() の結果を検証せず DB へ渡さない。
  • ❌ スタック/DB エラー本文をレスポンスに含めない。

典型例(コード片)

// app/api/users/route.ts
import { NextResponse } from 'next/server';
import { z } from 'zod';
import { requireUser } from '@/lib/auth';
import { logger } from '@/lib/logger';

const Body = z.object({ name: z.string().min(1).max(80) });

export async function POST(req: Request) {
  try {
    const session = await requireUser();
    const parsed = Body.safeParse(await req.json());
    if (!parsed.success) return NextResponse.json({ error: '入力が不正です' }, { status: 400 });
    // ... 処理
    return NextResponse.json({ ok: true }, { status: 201 });
  } catch (e) {
    logger.error('users.POST failed', { message: (e as Error).message });
    return NextResponse.json({ error: '処理に失敗しました' }, { status: 500 });
  }
}

アンチパターン

  • 認証なしの書き込みエンドポイントを公開する。
  • 入力未検証で req.json() を直接 DB に流す。
  • 500 のレスポンスに e.stack を入れて内部構造を漏らす。

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

atlas-search-vector

無料日本語概要

Use this skill when implementing full-text search, autocomplete, or vector/semantic search and RAG with MongoDB Atlas. Trigger words: 全文検索, あいまい検索, オートコンプリート, ベクトル検索, セマンティック検索, 類似検索, Atlas Search, $search, $vectorSearch, RAG, embedding.

Akira-Papa/claude-code-nextjs-mongo-template-162026年5月24日 更新

auth-better-auth

無料日本語概要

Use this skill when implementing sign-in, sessions, authorization checks, or protecting routes and Server Actions. Trigger words: 認証, ログイン, サインイン, セッション, 認可, 権限チェック, Better Auth, Auth.js, 保護, ミドルウェア, getSession.

Akira-Papa/claude-code-nextjs-mongo-template-162026年5月24日 更新

bootstrap

無料日本語概要

Use this skill when starting a new session, opening this project for the first time, or when you need to recall the project's tech stack, hard rules, and which other skills exist. Trigger words: セッション開始, このプロジェクト, 全体像, どのスキル, 何から, getting started, overview.

Akira-Papa/claude-code-nextjs-mongo-template-162026年5月24日 更新

ci-github-actions

無料日本語概要

Use this skill when setting up or modifying CI pipelines, GitHub Actions workflows, or automated checks (lint, typecheck, test, build) for this project. Trigger words: CI, GitHub Actions, ワークフロー, パイプライン, 自動テスト, lint チェック, typecheck, ビルド検証, .github/workflows.

Akira-Papa/claude-code-nextjs-mongo-template-162026年5月24日 更新

e2e-playwright

無料日本語概要

Use this skill when writing end-to-end tests, browser automation, or verifying user flows in a real browser. Trigger words: E2E, Playwright, ブラウザテスト, ユーザーフロー, 結合テスト, シナリオテスト, ログインテスト, getByRole, expect.

Akira-Papa/claude-code-nextjs-mongo-template-162026年5月24日 更新

error-boundaries

無料日本語概要

Use this skill when handling runtime errors, adding error.tsx or not-found.tsx, designing fallback UI, or deciding what to surface to users vs logs. Trigger words: エラー処理, error.tsx, not-found, 例外, フォールバック, エラーバウンダリ, try catch, ユーザー向けエラー, ログ.

Akira-Papa/claude-code-nextjs-mongo-template-162026年5月24日 更新

Akira-Papa のスキルをすべて見る

このスキルの問題を報告する