Designing a User Management system with JWTs, Ktor, and Exposed
Every app eventually needs to answer two questions: "who is this person?" and "what are they allowed to do?" Many tutorials either focus on integrating a specific authentication provider like Auth0 or Cognito, or else discuss low-level details like password hashing algorithms. Both of those stop short of the real question we should be asking ourselves: who actually is this person, and what does that mean in terms of how we manage their data and access?
