Next.js · Authentication · Fresh / Intern · Best Practice
Where should session checks happen in a Next.js app?
Short Interview Answer
Server Components, Server Actions, Route Handlers, and Middleware — defense in depth, not middleware alone.
Detailed Explanation
Middleware is a coarse gate; still authorize in data layer. Never trust client-only checks. Prefer httpOnly cookies for session tokens.