Recently I was tasked with implementing role-based security for a .NET API, based on the Active Directory groups the user is a member of. Easy, I thought initially, as there’s a well-documented way of doing this by adding [Authorize] annotations to controller methods.
The first problem I ran into was the API was designed to be used by a Node.js/React application. In this case (and this is a simplified description), users obviously don’t authenticate themselves directly with the API, but instead with the React application, via Active Directory Single Sign-On.
Notes initially published on my Bear Blog site.
A decade of software development and engineering taught me there are two design principles that I’d argue are more important than any particular pattern or design approach:
Code should be readable and self-explanatory. Each function or method (I use these terms interchangeably) should have a single, well-defined purpose. Code should be readable Programming languages are designed to provide human-readable abstractions of software, and, as such, code should be intelligible and relatively easy to work with.
I think I’ve found the ideal theme for my Hugo site. Mainroad is relatively simple in design, the layout is roughly what I was looking for, and it’s easier to customise. It still has tags and categories features that are essential for a site hosting technical documentation. I spent around six hours learning how the template works, re-arranging the content and tweaking the CSS to make it as clean as my MkDocs site.