How to secure Next.js API routes on public forms using server-side captcha verification
A Next.js API route remains publicly accessible regardless of whether its corresponding UI is hidden behind client-side conditions, making server-side validation essential. A practical example using Next.js App Router and the open-source FCaptcha library demonstrates how to protect a public contact form without requiring user accounts. In the setup, the browser collects a captcha token which the server independently verifies before processing any form submission or database write. The verification secret is kept strictly server-side and never exposed to the client, with the handler also enforcing origin checks, content-type validation, and message size limits. The complete example is available on a dedicated branch of the FCaptcha GitHub repository and runs locally with Node.js, launching both the Next.js app and FCaptcha server simultaneously.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in