3 ms·
> just autoincrement nonce=123 and revoke it any time. Does that revoke all tokens (shared "nonce") or update the token on next authentication? Would this "non
by kelson 10y ago
> just autoincrement nonce=123 and revoke it any time.
Does that revoke all tokens (shared "nonce") or update the token on next authentication? Would this "nonce" be stored in the database?
> nobody stores user mode in session
That's optimistic: https://github.com/akagadovskiy/ng-admin-jwt-auth/blob/master/js/authService.js https://github.com/akagadovskiy/ng-admin-jwt-auth/blob/maste...
> > but without the battle-tested implementations.
> "I don't know what's wrong but I'm kinda afraid to try".
Battle-tested implementations have dealt with (at least some of) these threats previously. New approaches often miss the lessons of past efforts, leaving themselves vulnerable to old attacks.
- homakov 10y ago> Would this "nonce" in the database? Only in revoked list=1,2,5,7 etc. Unlike storing all sessions, you only store revoked integers which takes way less space and achieves same revocation you wanted. > That's optimistic Nobody should store > leaving themselves vulnerable to old attacks Every new line of code is probably a vulnerability. That's life. BTW JWT indeed had some super stupid bug with alg=NONE before, and I would simply throw away "header" from JWT