5 ms·
i think he is discussing standard cookie session ids here, not access tokens. in many web applications, all the information you need is stored within that token
by ZephyrP 9y ago
i think he is discussing standard cookie session ids here, not access tokens. in many web applications, all the information you need is stored within that token and signed by a server-side secret.
- pritambaral 9y agoSame thing. How do you invalidate a signed cookie?