redirect() in Next.js works by throwing an internal error that the framework catches upstream to trigger navigation, so any catch block wide enough to enclose it turns a successful login into a logged failure.
Reality
- Evidence42
- Adoption
- Insufficient
- Hype gap+12
- Incentives55
- Confidence40
The failure depends on your Next.js version, your platform and the query itself, so it can pass locally and misbehave in one region; opting middleware into the Node runtime fixes it and hands back the edge placement you adopted middleware for.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence45
The automatic revert works exactly as documented. The documented example just has nowhere to put a failure, so a rejected server action reads to the user as a tick that quietly unticks a moment later.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+15
- Incentives55
- Confidence60
Streaming sends the sidebar and the skeleton before getSession() comes back, so a logged-out visitor sees the shape of a dashboard until the redirect lands. Closing that gap costs first-byte time on every protected route.
Reality
- Evidence44
- Adoption
- Insufficient
- Hype gap+12
- Incentives52
- Confidence41
The Origin check that makes Server Actions CSRF-resistant is a property of how Next.js dispatches them, not of your code. Refactor into app/api and you inherit the flexibility, not the check.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+12
- Incentives58
- Confidence42
A reviewer of a dozen Next.js Stripe integrations says almost none guard against duplicate or out-of-order deliveries. The failure mode is a second welcome email and no error anywhere.
Reality
- Evidence42
- Adoption
- Insufficient
- Hype gap+18
- Incentives58
- Confidence48