Security

When Does Your Login System Need Its Own AuthServer?

Your developer says the login system should live in its own AuthServer. Is that necessary, or is it overengineering? Here's how to tell, using a real example from a framework I build with every day.