Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

Required fields*

4
  • It sounds like you're advocating for a layer responsible for filtering the data requested/submitted between the application layer and the infrastructure? Commented May 25, 2023 at 15:30
  • I'm not advocating, I'm explaining my experience with pure CA. If you take CA to the extreme (the dogmatic implementation) each layer implements security as best serves and it's up to you how to tie everything in the application layer. The pragmatic implementation will rely on libraries of frameworks, which implementation can spend several layers too but it's the framework (not you) who ties everything, so you only do the configuration. Commented May 25, 2023 at 15:40
  • CA doesn't have a business layer defined in the diagrams but does talk about business logic living in the App layer. My "advocating" remark was aimed at a conversation regarding adding in a new layer or augmenting the existing App layer? Commented May 26, 2023 at 11:17
  • Yes, CA doesn't refer to layers. Layers are mere organizational units we use to arrange code belonging to one or more of the CA "circles" we see in the diagram. I edited the answer to refer the circles instead of layers (layers are a bit subjective as you pointed) Commented May 26, 2023 at 14:16