Autentikasi dalam App Router mencakup beberapa lapisan — sesi, middleware, pemeriksaan sisi server, dan perlindungan Server Actions. Pendekatan modern lebih menyukai verifikasi sesi sisi server dibandingkan pemeriksaan hanya klien.
Mengapa penting
Strategi sesi
Cookie-based sessions (httpOnly cookie):
✓ Store a signed session id or encrypted JWT in an httpOnly, secure cookie
✓ httpOnly = not readable by JavaScript → protects against XSS token theft
✓ Use a library: Auth.js (NextAuth), Clerk, Lucia, or a custom solution
