Security
What the dev panel exposes, and why it does nothing outside development.
What runs in production
query(), revalidate() and tags(). They are the library. Everything else in the package is for development.
The demo component NextQueryDemo lives at @angelitolm/next-query/demo, not in the package root. It renders in production with only the entries you pass it and never calls the server, so it needs no dev guard. It is meant for docs and demos.
The panel is dev-only
- The query registry that feeds the panel exists only in
next dev. In a production build the code that fills it is removed. - The panel reads the
.nextcache files (Next's fetch cache) and shows response previews in development only. <NextQuery />rendersnulloutside development and is tree-shaken, so the production client bundle contains no panel code. The playground's production smoke test checks this on every production run.- The panel talks to the server through server actions. A server action is a public endpoint, like any other. Each one throws
next-query devtools are dev-onlyoutside development, and the tags the browser sends are validated before they are used.
next dev listens on your network
While next dev runs, anyone who can reach it (usually everyone on your LAN) can read previews of your cached fetch responses and query data, up to about 16 KB each, and revalidate tags. This is the same exposure as next dev itself. Do not run it on an untrusted network, and never expose a dev server to the internet.
What to keep in mind
- Fetch URLs, including query strings (which may carry keys), are sent to the panel in development too.
- A preview is the response body of a tagged fetch, or the data of a query, as JSON or text. If it is something private, it shows up in the panel in development.
- Revalidating is harmless by design: it expires cached data, and the next read refetches it.