Your Next.js API route is public—even if your UI isn’t.
Hiding a form behind a client-side condition doesn't make its API route private. Unless the route enforces its own checks, another client can call it directly. For a public contact form, you may not want to require an account. You still want the server to validate the request before it triggers an email or database write. This example uses a Next.js App Router route handler and self-hosted…
Public API routes in Next.js, even if not visible to users, remain accessible to anyone who knows their URL. This can be problematic for forms, as an attacker could submit data directly to the route. To prevent unauthorized access, a server needs to verify the request. The example demonstrates using Next.js App Router route handlers with a free open-source project called FCaptcha.
FCaptcha handles a client-side form submission, collects a token, and sends it to the server for validation. The server-side code then completes the verification process using the received token, ensuring that only legitimate submissions are processed.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.