L-autentikazzjoni fl-App Router tinfirex fuq diversi livelli — sessjonijiet, middleware, kontrolli tal-server-side, u protezzjoni tas-Server Actions. L-approċċ modern jippreferi verifikazzjoni tas-sessjoni tal-server-side għalkemm kontrolli tal-client biss.
Għaliex huwa importanti
Strateġija tas-sessjoni
Cookie-based sessions (httpOnly cookie):
✓ Store a signed session id or encrypted JWT in an httpOnly, secure cookie
✓ httpOnly = not readable by JavaScript → protects against XSS token theft
✓ Use a library: Auth.js (NextAuth), Clerk, Lucia, or a custom solution
