I am currently building a microservices based application in spring boot with the following services
- Auth server (Distributes access tokens)
- User service (User info like username, password, email, etc.)
- Various other unrelated services
When a user sends their credentials to the auth server, the auth server should verify that they are correct and then return an access token.
My question is, should I combine the auth server with the user service so looking up credentials is a simple database call, or should I keep them as separate applications and have them both point to the same shared database? Is there a better alternative?