Back to skills
SKILL.md
Data Access Layer
ASecuritySecure, reusable data access patterns with DTOs and Taint checks.
- 8 stars
- 0 votes
- 0 copies
- 3 views
- Added September 8, 2026
Works with
Security analysis
100/100Pro scans all 2 files and shows the line behind each finding
npx -y skills add ngxtm/devkit --skill data-access-layer --agent claude-codeAre you the author of Data Access Layer?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/ngxtm-data-access-layer)---
name: Next.js Data Access Layer
description: Secure, reusable data access patterns with DTOs and Taint checks.
metadata:
labels: [nextjs, dal, architecture, security]
triggers:
files: ['**/lib/data.ts', '**/services/*.ts', '**/dal/**']
keywords: [DAL, Data Access Layer, server-only, DTO]
---
# Data Access Layer (DAL)
## **Priority: P1 (HIGH)**
Centralize all data access (Database & External APIs) to ensure consistent security, authorization, and caching.
## Principles
1. **Server-Only**: Must include `import 'server-only'` to prevent Client bundling.
2. **Auth Co-location**: Auth checks (`session.role`) must be **inside** the DAL function.
3. **DTO Transformation**: Return plain objects (DTOs), never raw ORM instances.
4. **No Internal Fetch**: Call DAL functions directly. Do not `fetch('localhost/api')`.
## Implementation
| Approach | When to use | Reference |
| :-------------------- | :----------------------------------------------- | :---------------------------------- |
| **API Gateway (BFF)** | Enterprise apps with separated Backend (NestJS). | [Pattern A](references/patterns.md) |
| **Direct DB** | Fullstack apps or Admin Panels. | [Pattern B](references/patterns.md) |
## Limitations
- **Client Components**: Cannot import DAL files. Must use Server Actions or Route Handlers as bridges.
Files in this skill
- SKILL.md
- references/patterns.md
Attribution
Comments
Loading comments…