Lesson 25 / 25

A Next.js Review Checklist

Common issues to check before shipping.

Questions for every change

Does each route render the way you expect (check the build table)? Are Client Components small and at the leaves? Are props crossing the boundary serializable, and server-only modules marked? Is data cached and revalidated deliberately, using one caching model consistently? Do Server Actions and Route Handlers authenticate, authorise and validate? Do unknown resources return real 404s? Are metadata, loading and error states in place? Are images and fonts optimised? Are only public values prefixed NEXT_PUBLIC_? Does CI run next build?

The checklist

Use it in code review.

[ ] build table checked: no route unexpectedly dynamic
[ ] "use client" only where interactivity is needed, at the leaves
[ ] serializable props across the boundary; "server-only" on data modules
[ ] caching model chosen; revalidation next to every mutation
[ ] Server Actions + Route Handlers: authn, authz, schema validation
[ ] notFound() for missing resources (real 404)
[ ] metadata per route; loading.tsx / Suspense; error.tsx
[ ] next/image with sizes; next/font
[ ] secrets never NEXT_PUBLIC_; proxy is not the only auth check
[ ] next build in CI; docs checked for the version in use

Read the upgrade guide

Major versions change conventions (for example middleware to proxy, params as a Promise); follow the official upgrade guide and codemods.

Quick check: Which item belongs on a Next.js review checklist?

  • Make every component a Client Component
  • Prefix database URLs with NEXT_PUBLIC_
  • Server Actions validate input and check permissions
  • Return 200 for missing products
Answer

Server Actions validate input and check permissions — Secure, deliberate, verified.