Next.js's proxy.js reference warns: “A matcher change or a refactor that moves a Server Function to a different route can silently remove Proxy coverage.”
- Proxy sees every route. The reference says Proxy is invoked for every route in a project, so it calls for matchers that include or exclude routes precisely.
- Early in the chain. Proxy sits third in the reference's execution order, after the headers and redirects in next.config.js and before any route is matched.
- Server Functions ride along. The reference notes that Server Functions are not separate routes in that chain but POST requests to the route that uses them, so a matcher excluding a path skips them.
- Check inside the function. The same reference wants authentication and authorization verified inside each Server Function, not left to Proxy alone. A check placed there moves with the function.