Context
Surfaced while making UserInterface::getIdentity() return string (webware-core#22) and reviewing the write-at-Command / read-at-Query perimeter for usermanager.
Data
- Authentication routes through the bus, but the definition does not live there.
LoginMiddleware dispatches Query\AuthenticateUserQuery (src/Http/Middleware/LoginMiddleware.php:57), mapped to QueryHandler\AuthenticateUserHandler at src/ConfigProvider.php:287.
- The handler is a pass-through: it calls
$this->users->authenticate() and wraps the result (src/QueryHandler/AuthenticateUserHandler.php:24).
- The definition lives in
UserRepository::authenticate() (src/Repository/UserRepository.php:46): row lookup by configured credential, existence check, active check, hash comparison, and four LogEvent dispatches on the security channel (lines 54, 62, 72, 79).
- Side effects (event dispatch) therefore execute inside the persistence layer, reached from a query path.
LoginMiddleware logs Failed login attempt itself as well, so the failure path is logged twice.
UserRepositoryInterface::authenticate() (src/Repository/UserRepositoryInterface.php:25) exposes authentication as repository API, which makes the repository the authentication contract rather than a persistence detail.
- Direct callers:
LoginMiddleware in production; 4 cases in test/unit/Repository/UserRepositoryTest.php and 1 in test/integration/Repository/UserRepositoryIntegrationTest.php.
Scope
The definition belongs on the bus; the repository keeps persistence only. Open: whether the message remains a query or becomes a command.
Deferred - not part of this round.
Context
Surfaced while making
UserInterface::getIdentity()returnstring(webware-core#22) and reviewing the write-at-Command / read-at-Query perimeter for usermanager.Data
LoginMiddlewaredispatchesQuery\AuthenticateUserQuery(src/Http/Middleware/LoginMiddleware.php:57), mapped toQueryHandler\AuthenticateUserHandleratsrc/ConfigProvider.php:287.$this->users->authenticate()and wraps the result (src/QueryHandler/AuthenticateUserHandler.php:24).UserRepository::authenticate()(src/Repository/UserRepository.php:46): row lookup by configured credential, existence check,activecheck, hash comparison, and fourLogEventdispatches on the security channel (lines 54, 62, 72, 79).LoginMiddlewarelogsFailed login attemptitself as well, so the failure path is logged twice.UserRepositoryInterface::authenticate()(src/Repository/UserRepositoryInterface.php:25) exposes authentication as repository API, which makes the repository the authentication contract rather than a persistence detail.LoginMiddlewarein production; 4 cases intest/unit/Repository/UserRepositoryTest.phpand 1 intest/integration/Repository/UserRepositoryIntegrationTest.php.Scope
The definition belongs on the bus; the repository keeps persistence only. Open: whether the message remains a query or becomes a command.
Deferred - not part of this round.