Skip to main content
Introducing packages.sweber.dev
Documentation menuNext.js

Next.js

An API route for the viewer with access control.

createAuditHandler turns a Fetch API Request into a Response, so it fits Next.js route handlers, Remix loaders, Hono, Bun and Cloudflare Workers.

// app/api/audit/route.ts
import { createAuditHandler } from "@sweberdev/logarithm"
import { audit } from "@/lib/audit"
import { getSession } from "@/lib/auth"

export const GET = createAuditHandler({
  log: audit,
  async authorize() {
    const session = await getSession()
    if (!session || session.role !== "admin") return null // 403
    return { tenantId: session.orgId }
  },
})

authorize is the only access check. Return the tenant the caller may see; the handler scopes every query to it, so ?tenant= or a forged cursor cannot reach other customers.

Then render the view on an admin page:

// app/settings/activity/page.tsx
"use client"
import { AuditLog } from "@sweberdev/logarithm-react"
import "@sweberdev/logarithm-react/styles.css"

export default function ActivityPage() {
  return <AuditLog endpoint="/api/audit" locale="de-CH" />
}

Server components

Without an API route, pass a server action as fetchPage:

"use server"
export async function loadActivity(query: AuditQuery) {
  const session = await requireAdmin()
  return audit.with({ tenantId: session.orgId }).query(query)
}
<AuditLog fetchPage={loadActivity} />