Skip to slide
Chapter 11 · Security, Auth, and Multi-Tenancy
100 / 191

CHAPTER 11 · Security, Auth, and Multi-Tenancy · 2 / 9

Authentication

Use a proven auth system rather than rolling your own. The essentials:

  • Sessions or tokens carried on each request (a bearer token is a common, simple choice). A single middleware validates the credential and attaches the resolved identity (user id, email/roles) to the request for downstream code.
  • One chokepoint. Every protected route passes through the same auth middleware. Identity enters the system in exactly one place, which makes it auditable.
  • Fail closed. No valid credential → reject. Don't fall through to a default or anonymous identity for protected resources.
  • Support the integrations you need (email/password, OAuth, SSO) but keep the result uniform: a verified identity on the request.
← → arrow keys work too