Most Next.js authentication patterns fail silently by redirecting users instead of returning proper HTTP status codes. Learn how forbidden() and unauthorized() replace middleware redirects with semantic responses that work correctly for browsers, crawlers, and API clients.