5 ms·
Even with the exp claim if the user saves the token before they log out they can reuse it until it actually expires, you have to generate jtis and store them in
by natelaporte 11y ago
Even with the exp claim if the user saves the token before they log out they can reuse it until it actually expires, you have to generate jtis and store them in a blacklist which is what the author of the article meant (you still have to have the concept of a session on the server to be totally sure).
- merb 11y agoActually that is not a flaw at all. Expiration times should be low anyway by user facing tokens, sessions. Also why should you save a token before logout and reuse it? You could actually just re-login? And still if the session won't get deleted when pressing logout you have the exact same problem. Also there aren't many users pressing the logout Button anyway. Edit: Btw. Sessions have flaws. Tokens have flaws, too. However the Flaws the author writes aren't actually problems / flaws it's just FUD.
- rashkov 11y agoHi Merb, thanks for engaging with the article. I submitted it to get feedback like this as I would love to use jwt but it doesn't seem to have wide adoption or a whole lot of discussion and literature. I think the idea of a user holding onto old expired tokens assumes that the user is a malicious party. A more useful example would be if the token were stolen, so the malicious party would not respect any attempts to expire the token before its expiration time is up.