CHAPTER 11 · Security, Auth, and Multi-Tenancy · 2 / 9
Authentication
Use a proven auth system rather than rolling your own. The essentials:
- Sessions or tokens carried on each request (a bearer token is a common, simple choice). A single middleware validates the credential and attaches the resolved identity (user id, email/roles) to the request for downstream code.
- One chokepoint. Every protected route passes through the same auth middleware. Identity enters the system in exactly one place, which makes it auditable.
- Fail closed. No valid credential → reject. Don't fall through to a default or anonymous identity for protected resources.
- Support the integrations you need (email/password, OAuth, SSO) but keep the result uniform: a verified identity on the request.