Really liked the fail open vs fail-closed section. Easy to overlook until something goes wrong in production. Would you ever avoid caching auth decisions completely?
The Difference Between a Cache and a Lie
2 Comments
jmp
•
prasadekke
•
@[jmp] Yes — I avoid caching auth decisions unless the stale window is explicitly acceptable and there is always a source-of-truth fallback on miss or cache failure. If the cache becomes the only practical way to know whether access is allowed, fail-open turns an outage into a security issue and fail-closed turns it into an availability issue. In those cases I would rather pay the latency cost than treat cached permission as truth.
Please log in to add a comment.
🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.
Please log in to comment on this post.
More Posts
- © 2026 Coder Legion
- Feedback / Bug
- Privacy
- About Us
- Contacts
- You Tube
- Tiktok
- Premium Subscription
- Terms of Service
- Early Builders
chevron_left
10Posts
4Comments
11Connections
Senior Principal Software Engineer at Broadcom building backend platforms that stay fast, reliable, ... Show moreSenior Principal Software Engineer at Broadcom building backend platforms that stay fast, reliable, and secure as they grow into critical infrastructure. Background spans distributed systems, cloud infrastructure, databases, and enterprise security products across Broadcom, Meta, Amazon Web Services, Symantec, and BindView. Show less
More From prasadekke
Related Jobs
- Bilingual Store Associate (Spanish)Sherwin-Williams · Full time · Hagerstown, MD
- Software Engineer, Test & Infrastructure II (Bilingual Spanish)Vail Systems · Full time · Springfield, IL
- Full Stack Java/Go Developer (Bilingual English/Spanish)Dev Technology · Full time · Arlington, VA
Commenters (This Week)
JAgostoni
1 comment
mohammadhusain
1 comment
Fooj
1 comment
Contribute meaningful comments to climb the leaderboard and earn badges!