Security in Next 14 and T3

Can someone recommend some best practices for securing secretes?
I've read online about using a:
  1. Data access layer
  2. "server-only"
Should I be slapping a "server-only" on every server related function? Do I need to
do that for server actions since they already have "use server"?
Was this page helpful?