4 ms·
JWT docs aren't accurate. Also why not just store JWT in the cookie? It's pretty trivial to use JWT in a cookie and do a sliding refresh on server side when its
by throwasehasdwi 9y ago
JWT docs aren't accurate. Also why not just store JWT in the cookie? It's pretty trivial to use JWT in a cookie and do a sliding refresh on server side when its close to expiring. You can use JWT this way with zero code on the client.
Same with the "Random Token". You can easily just shove a secure random ID in a session cookie and use it. Doesn't pretty much every framework support this?
This docs is... not accurate for most of these.
- awinder 9y agoWouldn't you need client code to cover csrf cases?
- throwasehasdwi 9y agoyou just cover them with a CSRF token embedded in page like ye olde days :)
- ksri 9y ago> JWT docs aren't accurate? I'm curious - which portion of the document isn't accurate? > Why not store JWT in the cookie? At that point, it becomes a "stateless session cookie". It's a valid pattern, just called a different thing in the document. > Same with "Random Token" Yes, and the document calls it "Stateful session cookie", and even highlights that every framework supports it.
- zip1234 9y agoAlso, JWTs can be used with OAUTH2.