3 ms·
This article is deeply troubling from a factual standpoint and I hope people do more research when considering JWT. Points; 1) His terms are confusing and just
by Negative1 10y ago
This article is deeply troubling from a factual standpoint and I hope people do more research when considering JWT.
Points;
1) His terms are confusing and just plain wrong. Backwards even. For example, he calls storing an id in the token and session data server-side as stateful. That is incorrect; there is no state stored on the client, it is all server-side. That is by definition a stateless session token.
2) A lot of his claims of why people recommend JWT are unsubstantiated and frankly, I've never heard them before (like JWT is better for mobile... what)? Maybe I would feel better if he provided references but a lot of those points are just plain misinformed (or imo, made up).
3) "You will not need stateless sessions" is like saying O(n) performance is usually good enough. Well ok, until it isn't. Don't assume some worst case performance on your site won't occur. Build defensively, knowing where you might have a bottleneck (DB I/O for instance). It's not just 'future proofing". It's good engineering, damnit.
4) It's hard? Give me a break.
5) It's inflexible? You can store an entire JSON object in a JWT. That is incredible flexibility.
6) It's not that secure (whereas cookies in his opinion are)? This is just blatantly false.
Ok, I'm tired of debunking this article. Plain and simple, this article is not just misinformed but dangerously wrong. I appreciate Sven trying to share his insight with the community of developers but most of what he says is wrong.
I use JWT for stateless session management backed by some clever database optimizations (at least I like to think so). If you want to know more ask, but please, do not use this article to guide your decision on whether to use JWT (or a similar secure token scheme).