Warum Security am Runtime-Rand?
Domain, Ports und Application Layer bleiben frei von OAuth2, JWT und Keycloak. Security ist eine technische Eintrittsregel am Rand der Anwendung. Dadurch bleibt die Fachlogik testbar und transportneutral.
Entwurfsmuster
- Security Boundary
- Anti-Corruption Layer für Claims
- Method-Level Authorization
- Composition Root