What you'll learn
Production identity combines authentication, authorization, secure credential handling, session lifecycle, and auditable decisions. Real-time channels add connection state and backpressure.
By the end of this lesson, you'll be able to:
- Separate authentication and authorization
- Design secure session handling
- Operate real-time connections and graceful deployment
Core mental model
Use this decision table as a compact reference. Focus on what each tool means and when it earns its place in production code.
| Concept | What it means | Decision rule |
|---|---|---|
| Authentication | Establishes who a principal is | Verify credentials and rotate session identifiers |
| Authorization | Decides whether an action is allowed | Check role and resource ownership on every protected operation |
| Real-time channel | Long-lived bidirectional or server-push connection | Use only when polling or request/response cannot meet the need |
Professional workflow
Build the behavior in small, observable steps. Each step should leave something you can inspect or test.
- Describe the identity and live-service lifecycle boundary: inputs, outputs, state, timing, and expected failures.
- Implement the smallest correct path with names that expose intent.
- Add edge cases and failure handling before introducing abstractions.
- Verify behavior with realistic data and one deliberately adversarial example.
- Refactor only after the observable behavior is protected.
Make behavior observable
Guided code lab
Authorize from trusted identity and resource
The policy receives a verified principal and the actual record, not a client-provided role claim.
function canEditCourse(user, course) {
if (!user) return false;
if (user.role === "admin") return true;
return user.role === "instructor" && course.instructorId === user.id;
}Track live connections explicitly
Connection ownership enables broadcasts, backpressure decisions, and shutdown cleanup.
const clients = new Set();
server.on("connection", client => {
clients.add(client);
client.on("close", () => clients.delete(client));
});
function broadcast(message) {
for (const client of clients) {
if (client.readyState === client.OPEN) client.send(message);
}
}Production practice
Contract
Make the identity and live-service lifecycle boundary explicit with validated inputs, structured outputs, owned resources, and stable failures.
Verification
Exercise normal work, invalid input, dependency failure, concurrency, and graceful cleanup in automated tests.
Operations
Use structured logs, health signals, timeouts, and configuration that can change without editing source code.
Common failure mode
Independent workshop
Add identity and live progress updates to the course application.
Your finished workshop must include:
- Secure session cookie settings
- Owner/admin authorization tests
- Connection cleanup, health check, and graceful shutdown plan
Definition of done
Recap & quick check
Key takeaways
- Authentication establishes identity
- Authorization protects actions
- Passwords require slow specialized hashing
- Real-time connections are owned resources
Quick check
1. What does authorization answer?
2. Where should a browser session ID normally live?
3. What must happen to live connections during shutdown?
Keep the workshop. Later modules deliberately build on these decisions, so each exercise can become part of your final portfolio architecture.