Auth state and route access

Victory+ · Kidoodle.TV · APMC, 2026

One cookie-backed source for sign-in state, and pages that declare who can see them.

Context

Server-side rendered app, two brands, three kinds of visitor: registered users, guests and people who are not signed in.

Problem

Sign-in state lived in two stores that could drift apart between server and client. Route access was one large conditional that was hard to read and harder to debug.

Route access as a matrix. Each page declares whether registered users, guests or signed-out visitors can see it.

What I did

  1. Replaced the dual store with a single cookie-persisted source of truth.
  2. Each page now declares its access level (registered, guest or unauthenticated) in its route meta, and the middleware reads that.
  3. Moved brand differences into a per-app auth config, so both brands share one implementation.

Outcome

  • Access rules live on each page and can be read in one place.
  • Server and client agree on who is signed in.

Stack

Nuxt middleware, Pinia, Cookies, TypeScript

Want to talk about work like this?

I’m happy to go deeper on any of it, including what I’d do differently.