3 ms·
> JWT docs aren't accurate? I'm curious - which portion of the document isn't accurate? > Why not store JWT in the cookie? At that point, it becomes a "state
by ksri 9y ago
> JWT docs aren't accurate?
I'm curious - which portion of the document isn't accurate?
> Why not store JWT in the cookie?
At that point, it becomes a "stateless session cookie". It's a valid pattern, just called a different thing in the document.
> Same with "Random Token"
Yes, and the document calls it "Stateful session cookie", and even highlights that every framework supports it.