Access control based on client cookies — easily bypassable and insecure.
Access control enforced on the server using NextAuth — robust and secure.