You can securely have a client side redirect so long as the page’s content is invisible by default, and made visible by a server-side condition.
Yes, among other things