if you add x-middleware-subrequest header to your request to the next.js website it would be treated like it has already passed through the auth wall middleware. cozy php vibes
https://security.snyk.io/vuln/SNYK-JS-NEXT-9508709
Post #874
198