5 ms·
Except cookies are quite literally perfect for that - set the expiration to 30 minutes from issuance and it will automatically be expired with inactivity. Or bu
by scient 8y ago
Except cookies are quite literally perfect for that - set the expiration to 30 minutes from issuance and it will automatically be expired with inactivity. Or bumped on activity.
- deathanatos 8y agoYou shouldn't be trusting the client to expire your sessions for you. (That is, relying on a cookie's expiration to actually expire the session.) (Now, if you mean looking up a session token in a database and checking that for expiry, then yes, that works, but the only real difference between JWT and tokens then is the latter requiring a database query.)
- yen223 8y agoThe more important difference between JWT and tokens is that the former requires you to trust that your encryption mechanism is foolproof, whereas the latter doesn't.
- deathanatos 8y agoSession tokens (an unguessable identifier that identifies server-side stored session data), while they don't need to be encrypted or signed, the identifier should usually be cryptographically random, however, so you can still get into trouble there. JWTs don't have to be encrypted. (And IME, typically aren't.) They need to be signed, but the algorithms that do this are common, well-understood algorithms. Some of them are likely being used by TLS to protect your session anyways. If they're not foolproof, you have bigger issues than JWT. If you are referring to the implementation, then sure, but the same concerns exist about your implementation of TLS, and the same advice applies: use a well-known, hopefully well tested library.
- nbevans 8y agoCookies are implementation dependent. It's quite possible that a user agent doesn't honour what you instructed it to do regarding the expiration of a cookie. JWT however... your server side can validate its own token in whatever ways it wants (including expiration). You can't get more secure than that.
- icebraining 8y agoIf you checking the session on the server, you might as well just use a token in a cookie. The point of the JWT complexity is to avoid that.
- nbevans 8y agoJWT tokens being passed via cookies is a valid use case.