PluginBench
Rule

nextjs15 supabase

via PatrickJS/awesome-cursorrules

27 architecture rules for Next.js 15 + Supabase preventing auth, params, and security hallucinations

What is nextjs15 supabase?

A comprehensive rule set for building secure Next.js 15 applications with Supabase, TypeScript strict mode, and shadcn/ui. Prevents common AI-generated mistakes like using getSession() instead of getUser(), synchronous params access, deprecated auth imports, missing RLS policies, and Stripe key exposure. Designed for Cursor Agent and Claude Code.

  • Enforces server-side auth verification with getUser() instead of insecure getSession()
  • Requires async/await for params and searchParams in Next.js 15 to prevent runtime crashes
  • Mandates @supabase/ssr over deprecated @supabase/auth-helpers-nextjs
  • Ensures all database tables have Row Level Security (RLS) enabled with policies
  • Enforces Server Actions for all data mutations with Zod validation and ActionResponse types
  • Requires error boundaries (loading.tsx, error.tsx) for data-fetching pages

Applies to

File patterns this rule matches.

**/*
Rule definition (reference)

Source of truth, from the repository.

Next.js 15 + Supabase Architecture Rules

You are an expert Next.js 15 developer working with Supabase, TypeScript (strict), and shadcn/ui. Follow ALL rules below unconditionally. If you are tempted to deviate, re-read the rule.

Tech Stack

  • Framework: Next.js 15 (App Router) with React 19
  • Language: TypeScript (strict mode)
  • Styling: Tailwind CSS + shadcn/ui
  • Database: Supabase (PostgreSQL + RLS)
  • Auth: Supabase SSR (cookie-based, @supabase/ssr)
  • Validation: Zod
  • Payments: Stripe (server-side only)

RULE 1: NEVER use getSession() on the server

SECURITY CRITICAL. getSession() reads the JWT from cookies WITHOUT verifying it. A forged cookie passes silently. ALWAYS use getUser() for server-side auth.

// ✅ CORRECT — verified with Supabase auth server
const supabase = await createClient()
const { data: { user } } = await supabase.auth.getUser()
if (!user) redirect('/login')

// ❌ WRONG — reads JWT without verification, session can be forged
const { data: { session } } = await supabase.auth.getSession()

RULE 2: NEVER access params synchronously in Next.js 15

In Next.js 15, params and searchParams are Promises. Synchronous access compiles but crashes at runtime.

// ✅ CORRECT
export default async function Page({ params }: { params: Promise<{ id: string }> }) {
  const { id } = await params
}

// ❌ WRONG — runtime crash
export default function Page({ params }: { params: { id: string } }) {
  const { id } = params // TypeError at runtime
}

RULE 3: NEVER import from @supabase/auth-helpers-nextjs

This package is deprecated. It does NOT work with Next.js 15 App Router cookies. ALWAYS use @supabase/ssr with manual cookie handling.

// ✅ CORRECT
import { createServerClient } from '@supabase/ssr'

// ❌ WRONG — deprecated, broken with App Router
import { createServerComponentClient } from '@supabase/auth-helpers-nextjs'

RULE 4: All database tables MUST have RLS enabled

Every Supabase table must have Row Level Security enabled. Without RLS, any user with the anon key can read ALL data from the table.

-- ✅ Always add after CREATE TABLE:
ALTER TABLE public.my_table ENABLE ROW LEVEL SECURITY;

CREATE POLICY "Users can only read their own data"
  ON public.my_table FOR SELECT
  USING (auth.uid() = user_id);

RULE 5: Default to Server Components

Only add 'use client' when the component needs interactivity (event handlers, useState, useEffect). Push 'use client' to the smallest leaf component possible.

RULE 6: All mutations via Server Actions

All data mutations happen through Server Actions, never client-side fetch(). Always validate with Zod, authenticate with getUser(), and return ActionResponse<T>.

'use server'
import { z } from 'zod'

type ActionResponse<T = void> =
  | { success: true; data: T }
  | { success: false; error: string }

const Schema = z.object({ title: z.string().min(1).max(200) })

export async function createItem(input: unknown): Promise<ActionResponse> {
  const supabase = await createClient()
  const { data: { user } } = await supabase.auth.getUser()
  if (!user) return { success: false, error: 'Unauthorized' }

  const result = Schema.safeParse(input)
  if (!result.success) return { success: false, error: 'Invalid input' }

  const { error } = await supabase.from('items').insert({ ...result.data, user_id: user.id })
  if (error) return { success: false, error: 'Failed to create item' }

  revalidatePath('/items')
  return { success: true, data: undefined }
}

RULE 7: Error boundaries for every data-fetching page

Every page that fetches data MUST have sibling loading.tsx and error.tsx files.

RULE 8: NEVER expose Stripe secret keys

Stripe keys starting with sk_ must NEVER be in NEXT_PUBLIC_ variables. Use process.env.STRIPE_SECRET_KEY (server-only).

RULE 9: TypeScript strict mode, no any

NEVER use any. Use unknown with Zod validation or type narrowing. tsconfig.json MUST have strict: true.

RULE 10: Middleware is for session REFRESH only

NEVER put auth enforcement in Next.js middleware. Middleware runs on Edge Runtime and cannot verify Supabase JWTs. Auth enforcement belongs in layouts/pages with getUser().


Full rule set (27 rules) available at: https://github.com/vibestackdev/vibe-stack Quick install: npx vibe-stack-rules init

Related rules

Node.js and Express.js best practices for backend development

**/*.js +2
41k
via PatrickJS/awesome-cursorrules

Node.js + MongoDB + Express setup guide for multi-entry pool management with JWT auth and admin approval workflows.

**/*
41k
via PatrickJS/awesome-cursorrules

Node.js + Express + MongoDB + JWT + React stack rules for sports pool management systems.

**/*
41k
via PatrickJS/awesome-cursorrules

DRY and SOLID principles integration for optimization development in Cursor.

**/*
41k
via PatrickJS/awesome-cursorrules

Expert guidance for writing clear, optimized Rell blockchain code on Chromia.

**/*
41k
via PatrickJS/awesome-cursorrules

Expert guidance for pandas, scikit-learn, and Jupyter-based data analysis workflows.

**/*
41k
via PatrickJS/awesome-cursorrules