---
title: "Edge-functions | Netlify Changelog"
description: "Get the latest updates on Netlify products and features to meet your developer needs."
source: "https://www.netlify.com/changelog/tag/edge-functions/"
last_updated: "2026-10-08T07:08:32.000Z"
---
# Posts tagged "Edge-functions"

All Tags Agent-runners AI Ai-gateway Angular Astro AX Billing Build CLI Database Design Devtools Domains E-commerce Edge-functions Extensions Forms Framework Functions Logs Next.js Nuxt.js Remix SDK Security Sveltekit Updates Workflow  [Subscribe to feed](https://www.netlify.com/changelog/tag/edge-functions/feed.xml)

-   [
    
    ## Know who is visiting your protected site, right from your functions
    
    ](/changelog/2026-10-07-context-user-in-functions/)
    
    October 7, 2026
    
    -   [functions](/changelog/tag/functions/)
    -   [edge functions](/changelog/tag/edge-functions/)
    -   [security](/changelog/tag/security/)
    
    On private projects and sites protected with Netlify team login, your Netlify Functions and Edge Functions can now see who is making the request. The signed-in Netlify user is available as `context.user`, with their user ID, email address, and when their access expires.
    
    This function returns the signed-in user’s ID, email address, and access expiry as JSON at `/whoami`, and responds with a `401` when `context.user` isn’t set:
    
    netlify/functions/whoami.ts
    
    ```
    import type { Config, Context } from '@netlify/functions'
    export default async (req: Request, context: Context) => {  if (!context.user) {    return new Response('Unauthorized', { status: 401 })  }
      return Response.json({    id: context.user.id,    email: context.user.email,    expiresAt: context.user.expiresAt.toISOString(),  })}
    export const config: Config = { path: '/whoami' }
    ```
    
    Previously, protecting a site meant Netlify checked who could visit, but your code couldn’t tell who they were. Knowing who’s on the other end meant adding a second login of your own on top.
    
    Now Netlify verifies the visitor at the edge and passes their identity to your code. Because `context.user` comes from Netlify and not from the request, a visitor can’t impersonate someone else by sending their own headers.
    
    With `context.user`, you can build on the login your team already uses. Examples like:
    
    -   Internal dashboards and admin tools that show each person their own data
    -   Audit logs that record who made a change or triggered an action
    -   Approval and review workflows that know who approved what
    -   Per-person settings, permissions, or feature access inside an internal app
    
    Learn more in the Netlify documentation:
    
    -   [`context.user` in Netlify Functions](https://docs.netlify.com/build/functions/api/#user)
    -   [`context.user` in Edge Functions](https://docs.netlify.com/build/edge-functions/api/#user)
    -   [Private projects](https://docs.netlify.com/manage/security/secure-access-to-sites/project-visibility/)
    -   [Team login protection](https://docs.netlify.com/manage/security/secure-access-to-sites/password-protection/#basic-password-protection-versus-team-login-protection)
    
    [Permalink to Know who is visiting your protected site, right from your functions Permalink](/changelog/2026-10-07-context-user-in-functions/)