Sessions, password hashing and JSON Web Tokens belong to the API: Cookies and Auth builds them in Express 24,430 , Cryptography explains the primitives underneath, and Security and Rate Limits hardens the API itself.
What is specific to Next.js 10,514 is placement. One App Router request is served by several independent pieces of code — the proxy, a chain of layouts, a page, a Server Action, a route handler — and each is an entry point a request can reach without passing through the others. The resulting mistake always has the same shape: the check is written in the one place the developer happened to be looking at.
A logged-out visitor cannot open the dashboard because proxy.ts redirects them. A logged-in reader never sees the delete button because the page refuses to render it. Neither fact stops a curl 3,008 POST aimed at the Server Action that button would have called: Server Functions are not routes of their own but POSTs to the route that uses them, so the page never rendered and the proxy saw a signed-in user asking for a page they may see.
