5 ms·
I've written about this at length here: https://paragonie.com/blog/2017/03/jwt-json-web-tokens-is-bad-standard-that-everyone-should-avoid https://paragonie.com/
by CiPHPerCoder 9y ago
I've written about this at length here: https://paragonie.com/blog/2017/03/jwt-json-web-tokens-is-bad-standard-that-everyone-should-avoid https://paragonie.com/blog/2017/03/jwt-json-web-tokens-is-ba...
(It's also the first link in the README for the project this Show HN is linking to, FWIW)
- treve 9y agoThose are mostly the drawbacks of JWT, less so using stateless sessions altogether. I found some additional reasons from a page that was linked from that last link here: http://cryto.net/~joepie91/blog/2016/06/13/stop-using-jwt-for-sessions/ http://cryto.net/~joepie91/blog/2016/06/13/stop-using-jwt-fo... * They take up more space * You cannot invalidate individual JWT tokens The other reasons seem a bit weaker. In your opinion, are those also the reasons why you wouldn't use PAST for stateless sessions?
- CiPHPerCoder 9y ago> In your opinion, are those also the reasons why you wouldn't use PAST for stateless sessions? Yep