2 ms·
"most applications should store it in a cookie" Why do you think that most application should store JWT token in the cookie? Both approaches have their pros/co
by hawkweed 10y ago
"most applications should store it in a cookie"
Why do you think that most application should store JWT token in the cookie? Both approaches have their pros/cons.
- wwalser 10y agoCookies have several security features built in and if all you're storing is a session identifier they are generally better than a JWT from a size perspective. This does a better job that I'm going to try for in a HN comment: http://cryto.net/~joepie91/blog/2016/06/13/stop-using-jwt-for-sessions/ http://cryto.net/~joepie91/blog/2016/06/13/stop-using-jwt-fo...