Prompt
Our auth code is brittle and hard to maintain
Latest observation
That’s a very common pain point. Auth tends to get brittle because it mixes security, session state, token handling, edge cases, and app-specific rules all in one place.
A good way to fix it is to make the auth system:
-
Centralized
Put all auth logic behind a single module/service instead of scattering checks across the app. -
Explicit about state
Model auth states clearly:- unauthenticated
- authenticating
- authenticated
- refreshing
- expired / revoked
- error
-
Separated by responsibility
Split into smaller pieces:- token storage
- token refresh
- request signing
- user/session lookup
- permission checks
- UI auth state
-
Typed and predictable
Use well-defined interfaces and return types so callers don’t guess what auth functions do. -
Tested around edge cases
Especially:- expired tokens
- concurrent refresh requests
- logout during API calls
- partial session corruption
- clock skew
- network failures during refresh
-
Free of hidden side effects
Avoid auth helpers that silently mutate global state, retry unexpectedly, or depend on ambient variables. -
Built with a single source of truth
Don’t store the same auth truth in multiple places unless there’s a clear synchronization strategy.
If you want, I can help in one of three ways:
- review your current auth design and point out brittleness
- propose a cleaner architecture for auth in your stack
- help refactor a specific auth flow if you paste code
If you share:
- your stack/language
- how you store tokens/sessions
- where the brittleness shows up
…I can give much more concrete guidance.