Seems like many people are trying to shoehorn their codebase [2] (!!) to make it work with the way the library manages sign-in flow, redirects, cookies, logout, etc. [3]
These were solved problems in the MEAN stack era with middlewares, but now that Next.js/react is the trend, people are doing everything they can to make it work - from relaxing security configs, to stashing things in the JWT just so some callback can get an additional piece of data [4].
[1] https://github.com/jaredhanson/passport
[2] https://github.com/nextauthjs/next-auth/issues/600#issuecomm...
[3] https://stackoverflow.com/questions/tagged/next-auth?sort=Mo...
[4] https://stackoverflow.com/questions/64576733/where-and-how-t...
EDIT: more links in case it helps the authors improve DX