4 ms·
This seems to be targeted at web apps. I take it I don't need to remove JWT token support from all of my mobile applications?
by Charlie_26 8y ago
This seems to be targeted at web apps. I take it I don't need to remove JWT token support from all of my mobile applications?
- KirinDave 8y agoThe problems with JWTs go well beyond "how do we do session invalidation." However, since mobile apps tend to be SSL encrypted on devices that don't reveal contents to users, you've often got a lot more leeway than the transparent condition web apps suffer. I know my app didn't have any real security challenges until we had a website with actionable data.