Nuxt · NUXT0037

Route middleware does not secure API routes

Flags route middleware API security in Nuxt middleware code before it leaks into runtime behavior.
NUXT0037vite-doctor/nuxtmiddlewarewarnSuggestion

Run this rule

pnpm nuxt doctor --rules nuxt/middleware/no-route-middleware-api-security

Why it matters

Navigation helpers only work correctly in the runtime they were designed for. Returning the navigation result keeps redirects and aborts observable to Nuxt.

Remove route middleware API security, or move it to the Nuxt runtime/API that owns that behavior.

Example

Keep API authorization on the server

Before

export default defineNuxtRouteMiddleware((to) => {
  if (!to.query.token) return abortNavigation()
})

After

export default defineEventHandler((event) => {
  const token = getQuery(event).token
  if (!token) throw createError({ statusCode: 401 })
})
Copyright © 2026