Function
The route's locale, for the sign-in redirect
The validated session
The proxy only looks for a session cookie; this validates it. A cookie that
does not resolve to a live session — forged, expired, revoked by a password
reset — redirects to sign-in. Layouts call it, and a layout does not know
the requested path, so this redirect carries no next; the proxy's
redirect, which covers the common case of no cookie at all, does.
The server-side session check every personal route runs before rendering.