4 ms·
This doesn't solve the criticism against JWT being used for sessions, which is one of the main point against JWT expressed in the very site linked at the top of
by Daycrawler 9y ago
This doesn't solve the criticism against JWT being used for sessions, which is one of the main point against JWT expressed in the very site linked at the top of the README.
- CiPHPerCoder 9y agoThere's nothing I can do at this layer that will stop people from using JWT/PAST/etc. as an attempt to build stateless session management systems for some ill-conceived "horizontal scalability" requirements, except maybe continue to tell people this is a bad idea and don't do that. The rest of the points (i.e. the problems with the JOSE standards) are what PAST seeks to solve. The "do not misuse" problem is more complicated, and if I were to add e.g. "do not use this for stateless sessions" at the top in big red letters, that will only tell developers "this is unsafe, keep using JWT instead".
- enobrev 9y ago> that will only tell developers "this is unsafe, keep using JWT instead". That's a good point. Maybe a header in the readme/docs like "Stateless Sessions", followed by "Using PAST/JWT/etc. for stateless sessions is a terrible idea, because kittens will die needlessly and painfully [ obviously using an actual summary of why ]. Don't just take my word for it, here are some resources explaining further..."
- treve 9y agoWhy is this a bad idea exactly? I'm still very interested in the idea of using stateless sessions. Is it just that it's hard to expire sessions server-side, or is there more to it?
- CiPHPerCoder 9y agoI've written about this at length here: https://paragonie.com/blog/2017/03/jwt-json-web-tokens-is-bad-standard-that-everyone-should-avoid https://paragonie.com/blog/2017/03/jwt-json-web-tokens-is-ba... (It's also the first link in the README for the project this Show HN is linking to, FWIW)
- treve 9y agoThose are mostly the drawbacks of JWT, less so using stateless sessions altogether. I found some additional reasons from a page that was linked from that last link here: http://cryto.net/~joepie91/blog/2016/06/13/stop-using-jwt-for-sessions/ http://cryto.net/~joepie91/blog/2016/06/13/stop-using-jwt-fo... * They take up more space * You cannot invalidate individual JWT tokens The other reasons seem a bit weaker. In your opinion, are those also the reasons why you wouldn't use PAST for stateless sessions?
- CiPHPerCoder 9y ago> In your opinion, are those also the reasons why you wouldn't use PAST for stateless sessions? Yep