4 ms·
I don’t know about real world implementations but to answer the last question: IMO authorization responsibility belongs to the backend service. I like setups wh
by vbsteven 6y ago
I don’t know about real world implementations but to answer the last question: IMO authorization responsibility belongs to the backend service. I like setups where the API Gateway talks to Keycloak for authenticating a request and passes a JWT with user/role info to the backend. The backend can then use the info from the JWT to perform authorization, and if necessary performs extra queries against an ACL table (or service).