Posts tagged "Edge-functions"
-
On private projects and sites protected with Netlify team login, your Netlify Functions and Edge Functions can now see who is making the request. The signed-in Netlify user is available as
context.user, with their user ID, email address, and when their access expires.This function returns the signed-in user’s ID, email address, and access expiry as JSON at
/whoami, and responds with a401whencontext.userisn’t set:netlify/functions/whoami.ts import type { Config, Context } from '@netlify/functions'export default async (req: Request, context: Context) => {if (!context.user) {return new Response('Unauthorized', { status: 401 })}return Response.json({id: context.user.id,email: context.user.email,expiresAt: context.user.expiresAt.toISOString(),})}export const config: Config = { path: '/whoami' }Previously, protecting a site meant Netlify checked who could visit, but your code couldn’t tell who they were. Knowing who’s on the other end meant adding a second login of your own on top.
Now Netlify verifies the visitor at the edge and passes their identity to your code. Because
context.usercomes from Netlify and not from the request, a visitor can’t impersonate someone else by sending their own headers.With
context.user, you can build on the login your team already uses. Examples like:- Internal dashboards and admin tools that show each person their own data
- Audit logs that record who made a change or triggered an action
- Approval and review workflows that know who approved what
- Per-person settings, permissions, or feature access inside an internal app
Learn more in the Netlify documentation: