VibeCoded

Is hiding buttons enough to protect admin pages?

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

No. Hiding a button or redirecting non-admins away from a page protects nothing, because anyone can call the API behind it directly. Every permission check has to happen on the server or in database rules, on every request. AI tools often put the check in the interface only, because that is where the prompt described it.

How it is bypassed

The browser developer tools show every request the app makes. A user copies the request the admin screen sends, such as POST /api/users/42/role, and sends it from their own session. If the server does not check their role, it works. The same applies to paid features hidden behind a plan check in the interface.

Where checks belong

  • In each API route or server action, using the role from the session.
  • In database rules: row level security or Firebase rules.
  • In edge and cloud functions, which often skip checks because they feel internal.

The interface check is for convenience only.

Test it

As a normal user, replay the requests an admin makes. Every one should be refused. See IDOR for the per-record version of the same problem.

The pattern to use

Write one server-side function that answers "may this user do this action on this record?" and call it from every route and server action, rather than writing the check inline each time. AI tools regenerate code and an inline check is easy to lose; a shared function is easy to keep. Back it with database rules where your backend supports them, so a missing check in code is still caught at the data layer.

Keep the interface checks as well: they improve the experience by hiding what a user cannot use. Just never rely on them. A useful test is to open the app as a normal user, copy every request from the admin screens out of an admin session, and replay them. Each should be refused.

Getting it checked

TrazTech offers vibe-coding QA and security review, listed from $2,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.

Get a scope for your app

Tell us what you built, what it stores and who is about to use it.

Get matched

Common questions

Is a secret admin URL enough?

No. URLs leak through history, logs and screenshots. Check the role on the server.

Does middleware protect my API routes?

Only if it runs on them. Page middleware often does not cover API routes or server actions. Check each route.