4 ms·
Token based auth doesn't need to be stateless. In fact in our current implementation it is not. If you use stateless like JWT (we had this before) you end up h
by lfrodrigues 10y ago
Token based auth doesn't need to be stateless. In fact in our current implementation it is not.
If you use stateless like JWT (we had this before) you end up having a huge problem: imagine a user wants to logout all the open accounts in different browsers.
How would you handle that? You would need to wait for the expiration of the token, a solution that is not that secure.
- smashed 10y agoOne solution is to store the token in localStorage, which supports events. You can listen for localStorage changes in all your tabs. When it changes, force a page reload or similar. Edit: typos
- lfrodrigues 10y agoI think you didn't understand the issue. Imagine you want to implement a "logout from all my sessions" like Facebook or Google have (sessions in different devices)