critical95%
Middleware Set-Cookie on prerendered static pages allows CDN caching of auth tokens
When middleware adds Set-Cookie headers to a response for a prerendered static page, Next.js preserves the page's original Cache-Control: s-maxage=31536000. Shared CDNs that obey s-maxage may cache and serve the response including sensitive Set-Cookie headers to other users, causing cross-user authentication token leakage.
