Securing Command Paths
It’s worth remembering that commands don’t exist.[35] They’re short-lived requests made to an aggregate. If the command is accepted, then the aggregate will emit the corresponding events. Reality hasn’t been affected until something emits an event.
This means that securing the command path becomes very much like securing access to a microservice (and many organizations and libraries actually use microservices as the entry point for commands). You’ll want to be certain that only those entities authorized to submit commands to your application can do so. No matter what identity is responsible for submitting a command, nothing should be able to bypass the validation performed by the aggregate.
Securing microservices is ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access