A login page alone doesn't protect your application.
If your dashboard contains private information, the application also needs to verify authentication before showing protected pages.
Identify Private Routes
Start by deciding which routes require authentication. For example: /dashboard /settings /account /billing
Public pages can remain accessible to everyone.
Check the Session
Your Next.js application can check the Supabase authentication session before rendering protected content. If there is no valid session, redirect the visitor to the login page.
Don't Trust the Frontend Alone
Hiding a navigation link isn't security. A user should not be able to access private data simply by manually entering a URL. Your backend/database permissions should also protect the underlying data.
Add Row Level Security
Supabase PostgreSQL supports Row Level Security policies. These policies can restrict which records an authenticated user can read or modify.
Test as Different Users
Create multiple test accounts. Make sure User A cannot access User B's private records. That test is more important than simply checking whether the dashboard redirects unauthenticated visitors.