Nuxt · Middleware

NUXT0074Review server authorization for auth-sensitive Nuxt API routes

Reviews auth-sensitive Nuxt server handlers against related middleware and guards.

Why it happens

Nuxt app route middleware runs during app navigation and cannot authorize a direct server API request.

Fix

Verify the server guard and enforce authorization in the handler or server middleware.

Example

Authorize the server request

Before

export default defineEventHandler(() => ({ private: true }))

After

export default defineEventHandler(async (event) => { await requireUserSession(event); return { private: true } })

Verify the fix

Run only this rule after editing so the report stays focused on the diagnostic you are closing:

pnpm vite-doctor . --framework nuxt --config doctor.config.ts --rules nuxt/review/api-authorization-coverage
Copyright © 2026