Auth Bypass in Middleware: How Next.js Fixed It and What You Can Learn

Today

Recap

Next.js will now automatically strip the x-middleware-subrequest header from incoming external requests.

(coming soon)