Securing Projections and Component State
Securing projections as well as aggregate and process manager state is a relatively straightforward process. You’ll need to ensure that only the authorized components can read from and write to the various data stores. In an ideal world, each one of them will have their own unique authentication which would prevent lateral escalation attacks if someone compromised only one component.
Securing these types of data depends almost entirely on the application or platform you’re using to store that data. Most data stores have, at the very least, credentials-based authentication, and many have robust authentication and authorization schemes.
As you set out to design and build your application and you’re evaluating ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access