User Functionality Part 2: Making Authentication a Framework Responsibility
Once I had decided that the website should have user accounts, I had to answer a fairly important question. Where should authentication live? The obvious answer, if I was thinking about the individual applications, would have been to put it in each application. After all, an application needs to know whether someone is logged in. But that immediately brought me back to the problem that had started the whole framework project in the first place. Duplication. If Publications had its own authentication system, and Marketplace had another, and another application had another, I would once again have several versions of essentially the same functionality. That wasn't what I wanted. If a user account belonged to the website rather than to an individual application, then authentication needed to belong to the platform as well. That was an important distinction. The applications shouldn't each have to work out how to authenticate a user. They should simply be able to ...