# Pattern: JWT / Bearer ## Middleware 1. Read `Authorization: Bearer ` 2. Parse/verify 3. Put `user_id` into context 4. Reject with code in 1xxxx if missing/invalid ## Service Always take `userID` from context for mutating ops. Never trust body `user_id` from client for ownership.