[{"data":1,"prerenderedAt":832},["ShallowReactive",2],{"navigation_docs":3,"-core-concepts-security-caveats":208,"-core-concepts-security-caveats-surround":827},[4,42,68,115,136,157],{"title":5,"path":6,"stem":7,"children":8,"icon":11},"Getting Started","\u002Fgetting-started","1.getting-started\u002F0.index",[9,12,17,22,27,32,37],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-sparkles",{"title":13,"path":14,"stem":15,"icon":16},"Installation","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F1.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"Configuration","\u002Fgetting-started\u002Fconfiguration","1.getting-started\u002F2.configuration","i-lucide-settings",{"title":23,"path":24,"stem":25,"icon":26},"Client Setup","\u002Fgetting-started\u002Fclient-setup","1.getting-started\u002F3.client-setup","i-lucide-monitor",{"title":28,"path":29,"stem":30,"icon":31},"Type Augmentation","\u002Fgetting-started\u002Ftype-augmentation","1.getting-started\u002F4.type-augmentation","i-lucide-type",{"title":33,"path":34,"stem":35,"icon":36},"Schema Generation (NuxtHub)","\u002Fgetting-started\u002Fschema-generation","1.getting-started\u002F5.schema-generation","i-lucide-database",{"title":38,"path":39,"stem":40,"icon":41},"How It Works","\u002Fgetting-started\u002Fhow-it-works","1.getting-started\u002F6.how-it-works","i-lucide-workflow",{"title":43,"path":44,"stem":45,"children":46,"page":67},"Core Concepts","\u002Fcore-concepts","2.core-concepts",[47,51,55,59,63],{"title":48,"path":49,"stem":50},"serverAuth()","\u002Fcore-concepts\u002Fserver-auth","2.core-concepts\u002F1.server-auth",{"title":52,"path":53,"stem":54},"Sessions","\u002Fcore-concepts\u002Fsessions","2.core-concepts\u002F2.sessions",{"title":56,"path":57,"stem":58},"Route Protection","\u002Fcore-concepts\u002Froute-protection","2.core-concepts\u002F3.route-protection",{"title":60,"path":61,"stem":62},"Auto‑Imports and Aliases","\u002Fcore-concepts\u002Fauto-imports-aliases","2.core-concepts\u002F4.auto-imports-aliases",{"title":64,"path":65,"stem":66},"Security & Caveats","\u002Fcore-concepts\u002Fsecurity-caveats","2.core-concepts\u002F5.security-caveats",false,{"title":69,"path":70,"stem":71,"children":72,"page":67},"Guides","\u002Fguides","3.guides",[73,77,82,86,90,94,99,103,107,111],{"title":74,"path":75,"stem":76},"Role‑Based Access","\u002Fguides\u002Frole-based-access","3.guides\u002F1.role-based-access",{"title":78,"path":79,"stem":80,"icon":81},"Setup diagnostics","\u002Fguides\u002Fdiagnostics","3.guides\u002F10.diagnostics","i-lucide-circle-alert",{"title":83,"path":84,"stem":85},"OAuth Providers","\u002Fguides\u002Foauth-providers","3.guides\u002F2.oauth-providers",{"title":87,"path":88,"stem":89},"Custom Database","\u002Fguides\u002Fcustom-database","3.guides\u002F3.custom-database",{"title":91,"path":92,"stem":93},"Database-less Mode","\u002Fguides\u002Fdatabase-less-mode","3.guides\u002F4.database-less-mode",{"title":95,"path":96,"stem":97,"icon":98},"External Auth Backend","\u002Fguides\u002Fexternal-auth-backend","3.guides\u002F5.external-auth-backend","i-lucide-server",{"title":100,"path":101,"stem":102},"Migrating from nuxt-auth-utils","\u002Fguides\u002Fmigrate-from-nuxt-auth-utils","3.guides\u002F6.migrate-from-nuxt-auth-utils",{"title":104,"path":105,"stem":106},"Two-Factor Authentication (TOTP + Backup Codes)","\u002Fguides\u002Ftwo-factor-auth","3.guides\u002F7.two-factor-auth",{"title":108,"path":109,"stem":110},"Testing","\u002Fguides\u002Ftesting","3.guides\u002F8.testing",{"title":112,"path":113,"stem":114},"Production Deployment","\u002Fguides\u002Fproduction-deployment","3.guides\u002F9.production-deployment",{"title":116,"path":117,"stem":118,"children":119,"page":67},"Integrations","\u002Fintegrations","4.integrations",[120,124,128,132],{"title":121,"path":122,"stem":123},"NuxtHub","\u002Fintegrations\u002Fnuxthub","4.integrations\u002F1.nuxthub",{"title":125,"path":126,"stem":127},"DevTools","\u002Fintegrations\u002Fdevtools","4.integrations\u002F2.devtools",{"title":129,"path":130,"stem":131},"Convex","\u002Fintegrations\u002Fconvex","4.integrations\u002F3.convex",{"title":133,"path":134,"stem":135},"i18n","\u002Fintegrations\u002Fi18n","4.integrations\u002F4.i18n",{"title":137,"path":138,"stem":139,"children":140,"page":67},"API Reference","\u002Fapi","5.api",[141,145,149,153],{"title":142,"path":143,"stem":144},"Composables","\u002Fapi\u002Fcomposables","5.api\u002F1.composables",{"title":146,"path":147,"stem":148},"Server Utilities","\u002Fapi\u002Fserver-utils","5.api\u002F2.server-utils",{"title":150,"path":151,"stem":152},"Components","\u002Fapi\u002Fcomponents","5.api\u002F3.components",{"title":154,"path":155,"stem":156},"Types","\u002Fapi\u002Ftypes","5.api\u002F4.types",{"title":158,"path":159,"stem":160,"children":161,"icon":81},"Errors","\u002Ferrors","6.errors\u002F0.index",[162,164,168,172,176,180,184,188,192,196,200,204],{"title":163,"path":159,"stem":160},"Overview",{"title":165,"path":166,"stem":167},"Auth configuration failed to load","\u002Ferrors\u002Fnuxt-auth-config-load-failed","6.errors\u002Fnuxt-auth-config-load-failed",{"title":169,"path":170,"stem":171},"Schema generator returned no code","\u002Ferrors\u002Fnuxt-auth-empty-schema","6.errors\u002Fnuxt-auth-empty-schema",{"title":173,"path":174,"stem":175},"Invalid server auth config export","\u002Ferrors\u002Fnuxt-auth-invalid-config-export","6.errors\u002Fnuxt-auth-invalid-config-export",{"title":177,"path":178,"stem":179},"Auth plugin path must be absolute","\u002Ferrors\u002Fnuxt-auth-invalid-plugin-source","6.errors\u002Fnuxt-auth-invalid-plugin-source",{"title":181,"path":182,"stem":183},"Missing auth configuration","\u002Ferrors\u002Fnuxt-auth-missing-config","6.errors\u002Fnuxt-auth-missing-config",{"title":185,"path":186,"stem":187},"NuxtHub database alias is missing","\u002Ferrors\u002Fnuxt-auth-missing-hub-db","6.errors\u002Fnuxt-auth-missing-hub-db",{"title":189,"path":190,"stem":191},"No database provider is enabled","\u002Ferrors\u002Fnuxt-auth-no-database-provider","6.errors\u002Fnuxt-auth-no-database-provider",{"title":193,"path":194,"stem":195},"Auth schema generation failed","\u002Ferrors\u002Fnuxt-auth-schema-generation-failed","6.errors\u002Fnuxt-auth-schema-generation-failed",{"title":197,"path":198,"stem":199},"Custom session storage is missing","\u002Ferrors\u002Fnuxt-auth-schema-storage-required","6.errors\u002Fnuxt-auth-schema-storage-required",{"title":201,"path":202,"stem":203},"Secondary storage in client-only mode","\u002Ferrors\u002Fnuxt-auth-storage-client-only","6.errors\u002Fnuxt-auth-storage-client-only",{"title":205,"path":206,"stem":207},"Unsupported database dialect","\u002Ferrors\u002Fnuxt-auth-unsupported-dialect","6.errors\u002Fnuxt-auth-unsupported-dialect",{"id":209,"title":64,"body":210,"description":821,"extension":822,"links":823,"meta":824,"navigation":287,"path":65,"seo":825,"stem":66,"__hash__":826},"docs\u002F2.core-concepts\u002F5.security-caveats.md",{"type":211,"value":212,"toc":811},"minimark",[213,217,222,225,229,245,356,363,367,390,414,431,442,447,450,456,613,618,675,686,749,753,764,771,775,786,789,792,796,807],[214,215,216],"p",{},"Use this page when you are moving from “it works locally” to “it is safe to deploy”.",[218,219,221],"h2",{"id":220},"client-redirects-are-not-security","Client redirects are not security",[214,223,224],{},"Client-side redirects improve UX but don't prevent unauthorized access. Always validate on the server.",[218,226,228],{"id":227},"csrf-origin-checks","CSRF \u002F origin checks",[214,230,231,232,236,237,240,241,244],{},"Better Auth performs origin checks for cookie-based requests (it validates ",[233,234,235],"code",{},"Origin"," \u002F ",[233,238,239],{},"Referer","). If you use multiple domains (custom domains, preview URLs, etc.), add them to ",[233,242,243],{},"trustedOrigins"," in your auth config.",[246,247,253],"pre",{"className":248,"code":249,"filename":250,"language":251,"meta":252,"style":252},"language-ts shiki shiki-themes one-light synthwave-84 synthwave-84","import { defineServerAuth } from '@nuxtjs\u002Fbetter-auth\u002Fconfig'\n\nexport default defineServerAuth({\n  trustedOrigins: [\n    'http:\u002F\u002Flocalhost:3000',\n    'https:\u002F\u002Fyour-domain.com',\n    'https:\u002F\u002Fyour-preview.workers.dev',\n  ],\n})\n","server\u002Fauth.config.ts","ts","",[233,254,255,282,289,306,319,328,336,344,350],{"__ignoreMap":252},[256,257,260,264,268,272,275,278],"span",{"class":258,"line":259},"line",1,[256,261,263],{"class":262},"sqe1H","import",[256,265,267],{"class":266},"s17Py"," { ",[256,269,271],{"class":270},"sYvLG","defineServerAuth",[256,273,274],{"class":266}," } ",[256,276,277],{"class":262},"from",[256,279,281],{"class":280},"sPAZv"," '@nuxtjs\u002Fbetter-auth\u002Fconfig'\n",[256,283,285],{"class":258,"line":284},2,[256,286,288],{"emptyLinePlaceholder":287},true,"\n",[256,290,292,295,299,303],{"class":258,"line":291},3,[256,293,294],{"class":262},"export",[256,296,298],{"class":297},"sKg8T"," default",[256,300,302],{"class":301},"sfT9l"," defineServerAuth",[256,304,305],{"class":266},"({\n",[256,307,309,312,316],{"class":258,"line":308},4,[256,310,311],{"class":270},"  trustedOrigins",[256,313,315],{"class":314},"sVnqq",":",[256,317,318],{"class":266}," [\n",[256,320,322,325],{"class":258,"line":321},5,[256,323,324],{"class":280},"    'http:\u002F\u002Flocalhost:3000'",[256,326,327],{"class":266},",\n",[256,329,331,334],{"class":258,"line":330},6,[256,332,333],{"class":280},"    'https:\u002F\u002Fyour-domain.com'",[256,335,327],{"class":266},[256,337,339,342],{"class":258,"line":338},7,[256,340,341],{"class":280},"    'https:\u002F\u002Fyour-preview.workers.dev'",[256,343,327],{"class":266},[256,345,347],{"class":258,"line":346},8,[256,348,349],{"class":266},"  ],\n",[256,351,353],{"class":258,"line":352},9,[256,354,355],{"class":266},"})\n",[357,358,359,360,362],"important",{},"If you deploy preview environments, you must include the preview origin in ",[233,361,243],{},". Otherwise, sign-in or sign-up requests can fail origin validation even when the API endpoint is healthy.",[218,364,366],{"id":365},"api-enforcement-behavior","API enforcement behavior",[214,368,369,370,373,374,377,378,381,382,385,386,389],{},"The built-in Nitro middleware checks ",[233,371,372],{},"routeRules.auth"," for app-owned ",[233,375,376],{},"\u002Fapi\u002F**"," routes. It skips Better Auth's ",[233,379,380],{},"\u002Fapi\u002Fauth\u002F**"," handler and known framework or module internals such as ",[233,383,384],{},"\u002Fapi\u002F_nuxt_icon\u002F**"," and ",[233,387,388],{},"\u002Fapi\u002F_better-auth\u002F**",", so broad route rules do not break auth, icons, or module tooling.",[214,391,392,393,396,397,396,400,396,403,396,406,409,410,413],{},"Do not combine an auth rule with ",[233,394,395],{},"cache",", ",[233,398,399],{},"swr",[233,401,402],{},"isr",[233,404,405],{},"static",[233,407,408],{},"prerender",", or ",[233,411,412],{},"proxy",". Those rules can run before authentication or reuse a response across users. The module rejects direct and inherited combinations during setup.",[214,415,416,417,396,420,396,423,426,427,430],{},"Known public asset namespaces (",[233,418,419],{},"\u002F_fonts",[233,421,422],{},"\u002F_ipx",[233,424,425],{},"\u002F_nuxt",", and ",[233,428,429],{},"\u002Fapi\u002F_nuxt_icon",", including their subpaths) are excluded from route-rule auth and its conflict validation in development and production. These paths must not contain private application routes. Authentication and devtools API paths still undergo conflict validation.",[214,432,433,434,437,438,441],{},"Registering a dev server handler does not exempt an application route: handlers can fall through to Nitro. For a custom public asset prefix, explicitly set ",[233,435,436],{},"auth: false",". If an asset module overwrites that route rule during setup, set the exclusion in a ",[233,439,440],{},"nitro:config"," hook.",[443,444,446],"h3",{"id":445},"customizing-unauthorized-behavior","Customizing Unauthorized Behavior",[214,448,449],{},"By default, unauthorized requests to protected routes receive a 401 response. To customize:",[214,451,452],{},[453,454,455],"strong",{},"Redirect to login instead of 401:",[246,457,460],{"className":248,"code":458,"filename":459,"language":251,"meta":252,"style":252},"import { sendRedirect } from 'h3'\n\nexport default defineEventHandler(async (event) => {\n  const session = await getUserSession(event)\n  if (!session && event.path.startsWith('\u002Fapi\u002Fprotected')) {\n    return sendRedirect(event, '\u002Flogin', 302)\n  }\n})\n","server\u002Fmiddleware\u002Fauth.ts",[233,461,462,478,482,513,539,579,604,609],{"__ignoreMap":252},[256,463,464,466,468,471,473,475],{"class":258,"line":259},[256,465,263],{"class":262},[256,467,267],{"class":266},[256,469,470],{"class":270},"sendRedirect",[256,472,274],{"class":266},[256,474,277],{"class":262},[256,476,477],{"class":280}," 'h3'\n",[256,479,480],{"class":258,"line":284},[256,481,288],{"emptyLinePlaceholder":287},[256,483,484,486,488,491,494,497,500,504,507,510],{"class":258,"line":291},[256,485,294],{"class":262},[256,487,298],{"class":297},[256,489,490],{"class":301}," defineEventHandler",[256,492,493],{"class":266},"(",[256,495,496],{"class":262},"async",[256,498,499],{"class":266}," (",[256,501,503],{"class":502},"sgisi","event",[256,505,506],{"class":266},") ",[256,508,509],{"class":262},"=>",[256,511,512],{"class":266}," {\n",[256,514,515,518,522,526,529,532,534,536],{"class":258,"line":308},[256,516,517],{"class":262},"  const",[256,519,521],{"class":520},"s6Rhl"," session",[256,523,525],{"class":524},"sQBpM"," =",[256,527,528],{"class":262}," await",[256,530,531],{"class":301}," getUserSession",[256,533,493],{"class":266},[256,535,503],{"class":270},[256,537,538],{"class":266},")\n",[256,540,541,544,546,550,553,556,560,563,566,568,571,573,576],{"class":258,"line":321},[256,542,543],{"class":262},"  if",[256,545,499],{"class":266},[256,547,549],{"class":548},"sn-Jc","!",[256,551,552],{"class":270},"session",[256,554,555],{"class":548}," &&",[256,557,559],{"class":558},"svFNh"," event",[256,561,562],{"class":266},".",[256,564,565],{"class":270},"path",[256,567,562],{"class":266},[256,569,570],{"class":301},"startsWith",[256,572,493],{"class":266},[256,574,575],{"class":280},"'\u002Fapi\u002Fprotected'",[256,577,578],{"class":266},")) {\n",[256,580,581,584,587,589,591,593,596,598,602],{"class":258,"line":330},[256,582,583],{"class":262},"    return",[256,585,586],{"class":301}," sendRedirect",[256,588,493],{"class":266},[256,590,503],{"class":270},[256,592,396],{"class":266},[256,594,595],{"class":280},"'\u002Flogin'",[256,597,396],{"class":266},[256,599,601],{"class":600},"s3ZNE","302",[256,603,538],{"class":266},[256,605,606],{"class":258,"line":338},[256,607,608],{"class":266},"  }\n",[256,610,611],{"class":258,"line":346},[256,612,355],{"class":266},[214,614,615],{},[453,616,617],{},"Return JSON error for API routes:",[246,619,621],{"className":248,"code":620,"language":251,"meta":252,"style":252},"\u002F\u002F This is the default behavior for \u002Fapi\u002F* routes\nthrow createError({\n  statusCode: 401,\n  data: { error: 'Authentication required' }\n})\n",[233,622,623,629,639,651,671],{"__ignoreMap":252},[256,624,625],{"class":258,"line":259},[256,626,628],{"class":627},"st7cf","\u002F\u002F This is the default behavior for \u002Fapi\u002F* routes\n",[256,630,631,634,637],{"class":258,"line":284},[256,632,633],{"class":262},"throw",[256,635,636],{"class":301}," createError",[256,638,305],{"class":266},[256,640,641,644,646,649],{"class":258,"line":291},[256,642,643],{"class":270},"  statusCode",[256,645,315],{"class":314},[256,647,648],{"class":600}," 401",[256,650,327],{"class":266},[256,652,653,656,658,660,663,665,668],{"class":258,"line":308},[256,654,655],{"class":270},"  data",[256,657,315],{"class":314},[256,659,267],{"class":266},[256,661,662],{"class":270},"error",[256,664,315],{"class":314},[256,666,667],{"class":280}," 'Authentication required'",[256,669,670],{"class":266}," }\n",[256,672,673],{"class":258,"line":321},[256,674,355],{"class":266},[214,676,677,678,681,682,685],{},"If you want different behavior (e.g. enforce ",[233,679,680],{},"auth: 'user'"," for APIs), add your own Nitro middleware and\u002For call ",[233,683,684],{},"requireUserSession(event)"," directly inside handlers.",[246,687,690],{"className":248,"code":688,"filename":689,"language":251,"meta":252,"style":252},"export default defineEventHandler(async (event) => {\n  await requireUserSession(event)\n  return { ok: true }\n})\n","server\u002Fapi\u002Fsecret.get.ts",[233,691,692,714,728,745],{"__ignoreMap":252},[256,693,694,696,698,700,702,704,706,708,710,712],{"class":258,"line":259},[256,695,294],{"class":262},[256,697,298],{"class":297},[256,699,490],{"class":301},[256,701,493],{"class":266},[256,703,496],{"class":262},[256,705,499],{"class":266},[256,707,503],{"class":502},[256,709,506],{"class":266},[256,711,509],{"class":262},[256,713,512],{"class":266},[256,715,716,719,722,724,726],{"class":258,"line":284},[256,717,718],{"class":262},"  await",[256,720,721],{"class":301}," requireUserSession",[256,723,493],{"class":266},[256,725,503],{"class":270},[256,727,538],{"class":266},[256,729,730,733,735,738,740,743],{"class":258,"line":291},[256,731,732],{"class":262},"  return",[256,734,267],{"class":266},[256,736,737],{"class":270},"ok",[256,739,315],{"class":314},[256,741,742],{"class":600}," true",[256,744,670],{"class":266},[256,746,747],{"class":258,"line":308},[256,748,355],{"class":266},[218,750,752],{"id":751},"default-login-route","Default login route",[214,754,755,756,759,760,763],{},"Unauthenticated users are redirected to ",[233,757,758],{},"\u002Flogin"," when a page requires auth. To use another path, set ",[233,761,762],{},"redirectTo"," on the protected route rule (or page meta auth object).",[765,766,767,768,770],"warning",{},"If your ",[233,769,762],{}," target does not exist, users will be redirected to a 404 page. Ensure redirect targets are valid app routes.",[218,772,774],{"id":773},"rate-limiting","Rate limiting",[214,776,777,778,785],{},"Better Auth includes a ",[779,780,784],"a",{"href":781,"rel":782},"https:\u002F\u002Fwww.better-auth.com\u002Fdocs\u002Fconcepts\u002Frate-limit",[783],"nofollow","built-in rate limiter",". It is enabled by default in production with a 60-second window and a maximum of 100 requests. It is disabled by default in development.",[214,787,788],{},"Rate-limit data is stored in memory by default. For serverless or multi-instance deployments, configure Better Auth to use database, secondary storage, or custom storage so instances do not rely on separate in-memory counters.",[790,791],"read-more",{"title":112,"to":113},[218,793,795],{"id":794},"devtools-in-production","DevTools in production",[214,797,798,799,802,803,806],{},"DevTools are automatically disabled when ",[233,800,801],{},"NODE_ENV=production",". The ",[233,804,805],{},"\u002Fapi\u002F_better-auth\u002F*"," endpoints and devtools page are never registered in production builds.",[808,809,810],"style",{},"html pre.shiki code .sqe1H, html code.shiki .sqe1H{--shiki-light:#A626A4;--shiki-default:#FEDE5D;--shiki-dark:#FEDE5D}html pre.shiki code .s17Py, html code.shiki .s17Py{--shiki-light:#383A42;--shiki-default:#BBBBBB;--shiki-dark:#BBBBBB}html pre.shiki code .sYvLG, html code.shiki .sYvLG{--shiki-light:#E45649;--shiki-default:#FF7EDB;--shiki-dark:#FF7EDB}html pre.shiki code .sPAZv, html code.shiki .sPAZv{--shiki-light:#50A14F;--shiki-default:#FF8B39;--shiki-dark:#FF8B39}html pre.shiki code .sKg8T, html code.shiki .sKg8T{--shiki-light:#E45649;--shiki-default:#FEDE5D;--shiki-dark:#FEDE5D}html pre.shiki code .sfT9l, html code.shiki .sfT9l{--shiki-light:#4078F2;--shiki-default:#36F9F6;--shiki-dark:#36F9F6}html pre.shiki code .sVnqq, html code.shiki .sVnqq{--shiki-light:#0184BC;--shiki-default:#B6B1B1;--shiki-dark:#B6B1B1}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sgisi, html code.shiki .sgisi{--shiki-light:#383A42;--shiki-light-font-style:inherit;--shiki-default:#FF7EDB;--shiki-default-font-style:italic;--shiki-dark:#FF7EDB;--shiki-dark-font-style:italic}html pre.shiki code .s6Rhl, html code.shiki .s6Rhl{--shiki-light:#986801;--shiki-default:#FF7EDB;--shiki-dark:#FF7EDB}html pre.shiki code .sQBpM, html code.shiki .sQBpM{--shiki-light:#0184BC;--shiki-default:#FFFFFFEE;--shiki-dark:#FFFFFFEE}html pre.shiki code .sn-Jc, html code.shiki .sn-Jc{--shiki-light:#0184BC;--shiki-default:#FEDE5D;--shiki-dark:#FEDE5D}html pre.shiki code .svFNh, html code.shiki .svFNh{--shiki-light:#383A42;--shiki-default:#FF7EDB;--shiki-dark:#FF7EDB}html pre.shiki code .s3ZNE, html code.shiki .s3ZNE{--shiki-light:#986801;--shiki-default:#F97E72;--shiki-dark:#F97E72}html pre.shiki code .st7cf, html code.shiki .st7cf{--shiki-light:#A0A1A7;--shiki-light-font-style:italic;--shiki-default:#848BBD;--shiki-default-font-style:italic;--shiki-dark:#848BBD;--shiki-dark-font-style:italic}",{"title":252,"searchDepth":284,"depth":284,"links":812},[813,814,815,818,819,820],{"id":220,"depth":284,"text":221},{"id":227,"depth":284,"text":228},{"id":365,"depth":284,"text":366,"children":816},[817],{"id":445,"depth":291,"text":446},{"id":751,"depth":284,"text":752},{"id":773,"depth":284,"text":774},{"id":794,"depth":284,"text":795},"What is enforced where, and what you should not assume.","md",null,{},{"title":64,"description":821},"Mk0o0NfjcoPcjNejWEI6iMTqN4ZGl69vthOvIq9Jgcg",[828,830],{"title":60,"path":61,"stem":62,"description":829,"children":-1},"What the module registers for you.",{"title":74,"path":75,"stem":76,"description":831,"children":-1},"Protect routes using generic field matching on AuthUser.",1791215142451]