3 ms·
Your #2 explanation is vague. Are you saying that the system had no server-side storage of whether a given user had admin rights or not? In #1 you mention "se
by sebular 10y ago
Your #2 explanation is vague. Are you saying that the system had no server-side storage of whether a given user had admin rights or not?
In #1 you mention "security practices like expiring session tokens in cookie" and then go on in #2 to say that the exact same thing isn't good enough. You do know that the T in JWT stands for "token", right?
Are you sending raw JWTs straight to the browser? Why? That's the big problem, not setting "admin=true" inside of a JWT. The data in a JWT is a claim that's meant to be verified by signing. It's no more and no less.
If you want to describe the OAuth implementation or something more substantial than a "cool kid" then it might be more illuminating, but you don't give any context.