Treat the action as an untrusted server entry point: authenticate, authorize ownership, validate the form input with Zod, and verify the request origin before deleting. Keep the action in an `actions.ts` server module, delegate the deletion to the DAL, and revalidate the exact post list/tag afterward. Never trust a hidden field or middleware alone for authorization.
Installs into .claude/skills of the current project.
Are you the author of Nextjs Security?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-nextjs-security-agent-skills-standard)
Treat the action as an untrusted server entry point: authenticate, authorize ownership, validate the form input with Zod, and verify the request origin before deleting. Keep the action in an `actions.ts` server module, delegate the deletion to the DAL, and revalidate the exact post list/tag afterward. Never trust a hidden field or middleware alone for authorization.