How do you implement authentication middleware?
Answer
Verify the credential or session once in middleware, load only the identity and claims needed by downstream handlers, and attach that trusted context to the request. Authorization middleware then checks whether that identity may perform the requested action.
Context
Express is a minimal Node.js HTTP framework. Compose routes from small middleware functions, validate untrusted input at the boundary, and send errors to one consistent error handler.
Example
Consider a production Express change: define the expected behavior and failure modes first, implement the smallest observable change, then verify it with a focused test or measurement. The right implementation depends on the system boundary and its constraints.
Practical considerations
- Choose the approach from the requirement and constraints, not from habit.
- Include validation, error handling, and cleanup where the boundary requires them.
- Verify the observable result with focused tests or measurement.
Follow-up prompts
- What failure mode would you expect if this were implemented incorrectly?
- How would you test this behaviour?
- What changes when the feature must scale to a larger application or team?
In practice
For this easy-level topic, make assumptions explicit, choose the smallest safe implementation, and verify the behavior at the relevant boundary.