Node.js · Authentication · Senior · Scenario
Where should auth middleware run relative to rate limiting?
Short Interview Answer
Rate-limit early (including unauthenticated), then authenticate, then authorize — but protect login endpoints specially.
Detailed Explanation
Credential stuffing needs strict limits on /login. Authenticated rate limits may be per-user. Order is an interview favorite.