Nuxt · Middleware

NUXT0037Route middleware does not secure API routes

Flags route middleware API security in Nuxt middleware code before it leaks into runtime behavior.

Why it happens

Navigation helpers only work correctly in the runtime they were designed for. Returning the navigation result keeps redirects and aborts observable to Nuxt.

Fix

Remove route middleware API security, or move it to the Nuxt runtime/API that owns that behavior.

Example

Keep API authorization on the server

Before

export default defineNuxtRouteMiddleware((to) => {
  if (!to.query.token) return abortNavigation()
})

After

export default defineEventHandler((event) => {
  const token = getQuery(event).token
  if (!token) throw createError({ statusCode: 401 })
})

Verify the fix

Run only this rule after editing so the report stays focused on the diagnostic you are closing:

pnpm nuxt doctor --rules nuxt/middleware/no-route-middleware-api-security
Copyright © 2026