Handling Cross-Cutting Concerns
Implement strategies for logging, authentication, and authorization without violating the Dependency Rule or polluting core logic.
Handling Cross-Cutting Concerns is a free Clean Architecture & Design Patterns in Practice lesson on CoddyKit — lesson 1 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Clean Architecture & Design Patterns in Practice learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.
What are Cross-Cutting Concerns?
In software development, cross-cutting concerns are aspects of a system that affect many parts of the application but are not part of its core business logic. Think of them as system-wide services.
- Logging: Recording events for debugging or auditing.
- Authentication: Verifying a user's identity.
- Authorization: Determining what an authenticated user can do.
- Caching: Storing frequently accessed data for faster retrieval.
- Transaction Management: Ensuring data consistency across multiple operations.
The Clean Architecture Dilemma
Clean Architecture emphasizes keeping your core business logic (Entities and Use Cases) independent of external frameworks and delivery mechanisms. This is enforced by the Dependency Rule: dependencies must only flow inwards.
The challenge arises because cross-cutting concerns often rely on specific external frameworks (e.g., a logging library, a security framework). How can we implement these concerns without violating the Dependency Rule and coupling our core logic to external details?
Logging Without Pollution
Let's take logging as an example. If a CreateUserUseCase directly calls a logging framework like Log4j or SLF4J, it creates a dependency on that specific framework.
CreateUserUseCase → Log4j
This violates the Dependency Rule because the inner layer (Use Case) would depend on an outer layer (Frameworks/Drivers). Our core logic should not care how logs are written, only that they need to be written.
Defining a Logging Port
To solve this, we introduce an interface in our inner (Use Case) layer. This interface, often called an Output Port, defines the contract for logging. The Use Case depends on this abstraction, not a concrete implementation.
package application.ports;
public interface ILogger {
void info(String message);
void error(String message, Throwable t);
}Implementing the Logger Adapter
The actual logging framework implementation lives in an outer layer (e.g., Infrastructure). This concrete class acts as an Adapter, implementing our ILogger port and delegating to the specific logging library.
Notice how ConsoleLogger depends on ILogger (an inner layer abstraction), respecting the Dependency Rule.
package infrastructure.logging;
import application.ports.ILogger; // Depends on inner layer
public class ConsoleLogger implements ILogger {
@Override
public void info(String message) {
System.out.println("[INFO] " + message);
}
@Override
public void error(String message, Throwable t) {
System.err.println("[ERROR] " + message + " - " + t.getMessage());
}
}Logger in a Use Case
Now, our CreateUserUseCase can depend on the ILogger interface. The concrete ConsoleLogger is injected at runtime, typically by a Dependency Injection (DI) container, but we'll do it manually here for clarity.
package application.usecases;
import application.ports.ILogger;
import infrastructure.logging.ConsoleLogger;
public class CreateUserUseCase {
private final ILogger logger;
public CreateUserUseCase(ILogger logger) {
this.logger = logger;
}
public void execute(String username) {
logger.info("Attempting to create user: " + username);
// ... business logic to create user ...
logger.info("User created successfully: " + username);
}
}
public class Main {
public static void main(String[] args) {
// Manual Dependency Injection for demonstration
ILogger consoleLogger = new ConsoleLogger();
CreateUserUseCase useCase = new CreateUserUseCase(consoleLogger);
useCase.execute("Alice");
}
}Handling Authentication
Authentication (verifying who a user is) should occur at the application's entry points, not within the core Use Cases. The Use Case should only receive already authenticated user information.
- Middleware/Filters: In web applications, these intercept requests before they reach controllers.
- Input Port Decorators: You can wrap a Use Case with a decorator that handles authentication before delegating to the actual Use Case.
This ensures the Use Case remains focused on business logic, free from security framework details.
Authorization with Policies
Authorization (what an authenticated user can do) is often more complex. While basic authorization can also be handled at the entry point, more granular checks might involve the Use Case.
- Authorization Policies: Define separate objects or services that encapsulate authorization rules.
- Interceptors/Aspects: Apply these policies around Use Case execution, checking permissions before the core logic runs.
- The Use Case might depend on an
IAuthorizationServiceinterface (another Port) to query specific permissions.
DI for Cross-Cutting Concerns
The overarching principle for handling cross-cutting concerns in Clean Architecture is the Dependency Inversion Principle (DIP).
- High-level modules (Use Cases) should not depend on low-level modules (frameworks).
- Both should depend on abstractions (interfaces).
- Abstractions are defined in the inner layers, and their concrete implementations reside in the outer layers, injected at runtime.
This keeps your core logic clean, testable, and independent of external technologies.
Applying Clean Concerns
Consider a ProcessOrderUseCase that needs to log critical steps. Which approach aligns best with Clean Architecture's Dependency Rule?
Recap: Keeping Core Clean
We've explored strategies to handle cross-cutting concerns like logging, authentication, and authorization within Clean Architecture:
- Abstract Concerns: Define interfaces (Ports) in inner layers for concerns like logging.
- Implement Adapters: Provide concrete implementations of these interfaces in outer layers (Adapters).
- Boundary Handling: Use middleware, decorators, or interceptors at application boundaries for authentication and authorization.
- Dependency Inversion: This principle is crucial for ensuring your core business logic remains clean, independent, and free from external framework details.
Frequently asked questions
Is the “Handling Cross-Cutting Concerns” lesson free?
Yes — the full text of “Handling Cross-Cutting Concerns” is free to read here on the web, and the Clean Architecture & Design Patterns in Practice course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Clean Architecture & Design Patterns in Practice course, upgrade to CoddyKit PRO.
What will I learn in “Handling Cross-Cutting Concerns”?
Implement strategies for logging, authentication, and authorization without violating the Dependency Rule or polluting core logic. You practise Clean Architecture & Design Patterns in Practice with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start Clean Architecture & Design Patterns in Practice?
No prior experience is required. Clean Architecture & Design Patterns in Practice on CoddyKit is structured for beginners through advanced learners; this is — lesson 1 of 4, so you can start here or from the beginning and move at your own pace.
How long does the “Handling Cross-Cutting Concerns” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this Clean Architecture & Design Patterns in Practice lesson?
Yes. Every Clean Architecture & Design Patterns in Practice lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- Handling Cross-Cutting Concerns
- Event-Driven Clean Architecture
- Clean Architecture in Microservices
- CQRS within Clean Architecture