How to use this reference
For an owned application, document where privileged data becomes renderable or serializable. Keep data access and permission checks together, validate action inputs, and minimize returned fields. Treat framework safeguards as additional protections around explicit authorization.
Before reading
- React Server Components and Server Actions concepts
- Authentication, object authorization and serialization basics
Context and limits
- The page is living framework guidance, not evidence that any deployed application is vulnerable.
- Taint APIs are experimental and supplement explicit data minimization; encrypted closures do not replace careful handling of sensitive data.
- A navigation version label was not treated as the version of this guidance.
Sources and provenance
- How to think about data security in Next.js Next.js / Vercel · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.