-
Notifications
You must be signed in to change notification settings - Fork 1
ADR: JWT
Megu edited this page Apr 1, 2026
·
2 revisions
Accepted
Game Y uses a microservices architecture (users-service and gameyapi). We need a secure, stateless way to share user identity across these services without forcing every API call to query a central database for session validation.
We will use JSON Web Tokens (JWT) for secure authentication.
- Flow: Upon login, the users-service generates a signed token containing userId and username.
- Secret Management: We use .env files for local development and GitHub Secrets for production to ensure the JWT_SECRET is never committed to version control.
- Validation: Consumer services (like gameyapi) extract and verify the token using a shared JWT_SECRET to identify the player.
- Session-based Authentication: Requires a centralized store (like Redis) to check session validity on every request. This introduces higher latency and a single point of failure.
- Opaque Tokens: The client receives a random string, but the resource server must still call the authentication service to "exchange" that string for user data, increasing network traffic.
- Performance: Services verify users locally, reducing network latency and database load.
- Decoupling: The gameyapi does not need a direct connection to the user database to verify identity.
- Scalability: Stateless tokens make it easier to scale microservices horizontally.
- Security Risk: If the JWT_SECRET is compromised, an attacker can impersonate any user
- Revocation: Tokens remain valid until expiration (2 hours); there is no built-in way to "force logout" a specific token instantly.
- Payload Size: All necessary user data must fit in the token, which is sent with every request.
Verification is successful when a user logs in via users-service and the resulting token is successfully used by gameyapi to attribute a game session to the correct userId.
YOVI en1a • © 2026 • Escuela de Ingeniería Informática
🏠 Home │
📂 Documentation │
🎮 Play now!
Sprint 0 (v0.1)
Sprint 1 (v0.1 Prototype)
Sprint 2 (v1.0)
Sprint 3 (v2.0)
- ADR: MongoDB
- ADR: Azure Host
- ADR: JWT
- ADR: Gatling
- ADR: bcrypt
- ADR: i18n
- ADR: Cucumber
- ADR: Playwright
- ADR: API REST - gameyapi