Next.js · Server Actions · Mid-Level · Scenario
What security issues exist with Server Actions?
Short Interview Answer
They are callable endpoints — must authenticate, authorize, validate inputs, and protect against CSRF/origin issues as designed by the framework version.
Detailed Explanation
Never trust client-sent IDs for ownership. Apply same rules as API routes. Avoid exporting overly broad server functions.