Microservice Authentication in a Social Media Application with Follower-Following-Block User Relationships

Viewed 90

I am currently building a microservice-based application for a social media app with user relationships similar to Instagram. I understand that the authentication for the app should occur in an API-gateway service, which checks if the user is authenticated and has a JWT token. After this authentication, the request can then be forwarded to the appropriate microservice which will handle the data retrieval and processing and then return it to the client. However, I am confused on how to authorize/authenticate users based on the follower-following-block model. For example, if I am user X and I am not following user Y, I should not be able to access user Y's posts or send messages to user Y. What in the api gateway microservice is stopping me from doing that? Am i supposed to implement both the user auth functionality, as well as the user relationship functionality within the api-gateway service? (i.e. the api gateway stores the user and user relationship information in a database) Or am i supposed to have a separate microservice which is queried every-time the user makes a request to ensure that the user is following/ not blocked by the user whose resources they are trying to access?

I have thought about this a lot, but cannot find a good solution online. I am looking for a big picture, architecture-based answer here.

Thanks in advance

0 Answers
Related