Phase 5 · Node.js & Full StackModule 35~52 min read

Authentication, Real-Time & Production

Add identity and live communication, then prepare a Node application for reliable deployment.

What you'll learn

Production identity combines authentication, authorization, secure credential handling, session lifecycle, and auditable decisions. Real-time channels add connection state and backpressure.

By the end of this lesson, you'll be able to:

  • Separate authentication and authorization
  • Design secure session handling
  • Operate real-time connections and graceful deployment

Core mental model

Use this decision table as a compact reference. Focus on what each tool means and when it earns its place in production code.

ConceptWhat it meansDecision rule
AuthenticationEstablishes who a principal isVerify credentials and rotate session identifiers
AuthorizationDecides whether an action is allowedCheck role and resource ownership on every protected operation
Real-time channelLong-lived bidirectional or server-push connectionUse only when polling or request/response cannot meet the need

Professional workflow

Build the behavior in small, observable steps. Each step should leave something you can inspect or test.

  1. Describe the identity and live-service lifecycle boundary: inputs, outputs, state, timing, and expected failures.
  2. Implement the smallest correct path with names that expose intent.
  3. Add edge cases and failure handling before introducing abstractions.
  4. Verify behavior with realistic data and one deliberately adversarial example.
  5. Refactor only after the observable behavior is protected.

Make behavior observable

Before optimizing or abstracting, make inputs, outputs, state changes, timing, and failure paths visible. JavaScript becomes much easier to reason about when hidden work is exposed.

Guided code lab

Authorize from trusted identity and resource

The policy receives a verified principal and the actual record, not a client-provided role claim.

authorization.js
function canEditCourse(user, course) {
  if (!user) return false;
  if (user.role === "admin") return true;
  return user.role === "instructor" && course.instructorId === user.id;
}

Track live connections explicitly

Connection ownership enables broadcasts, backpressure decisions, and shutdown cleanup.

connections.js
const clients = new Set();
server.on("connection", client => {
  clients.add(client);
  client.on("close", () => clients.delete(client));
});
function broadcast(message) {
  for (const client of clients) {
    if (client.readyState === client.OPEN) client.send(message);
  }
}

Production practice

Contract

Make the identity and live-service lifecycle boundary explicit with validated inputs, structured outputs, owned resources, and stable failures.

Verification

Exercise normal work, invalid input, dependency failure, concurrency, and graceful cleanup in automated tests.

Operations

Use structured logs, health signals, timeouts, and configuration that can change without editing source code.

Common failure mode

A valid session proves identity, not permission; every protected resource action still requires an authorization decision.

Independent workshop

Add identity and live progress updates to the course application.

Your finished workshop must include:

  • Secure session cookie settings
  • Owner/admin authorization tests
  • Connection cleanup, health check, and graceful shutdown plan

Definition of done

Demonstrate the happy path and at least two edge cases, keep responsibilities separated, and add a short note explaining one design choice.

Recap & quick check

Key takeaways

  • Authentication establishes identity
  • Authorization protects actions
  • Passwords require slow specialized hashing
  • Real-time connections are owned resources

Quick check

1. What does authorization answer?

2. Where should a browser session ID normally live?

3. What must happen to live connections during shutdown?

Keep the workshop. Later modules deliberately build on these decisions, so each exercise can become part of your final portfolio architecture.