It works with server-side before middleware, because server-side ones are omitted...
But when route-level one silently "overwrites" fake-auth, it might be confusing to the user. If not fix, can't we at least raise a warning in this case, saying that "Try to apply your middleware on server-level"?