3 ms·
Well, you don’t, so if that’s a requirement you’ve got to do it some other way.
by oxymoron 9y ago
Well, you don’t, so if that’s a requirement you’ve got to do it some other way.
- e12e 9y agoYou can rotate the secret to invalidate all tokens.
- tptacek 9y agoNo, you can't. That breaks all of your users, and so you'll rarely do it, even when it might be warranted. Don't engineer security countermeasures that you (a) might need to rely on and (b) will be afraid to use.
- e12e 9y agoGood points. But for some types of apps, you might have groups of users (a company, team, municipality) that you might be able to afford the cost of "everyone log in again". Or you might be able to safely log out everyone after business hours (if in the same timezone).