3 ms·
> That has nothing to do with JWTs. Progress! You're so close to understanding the article. It wasn't ever about JWTs in particular. It was a response to a wi
by CiPHPerCoder 8y ago
> That has nothing to do with JWTs.
Progress! You're so close to understanding the article.
It wasn't ever about JWTs in particular. It was a response to a widespread engineering antipattern of "storing all session state in a cookie then maybe encrypting or HMACing it so you don't have to store anything server-side". JWT was just how developers tended to implement this antipattern.
Like, literally, that was the entire point of the entire article that Sven wrote.
The examples of apps that do this have become less common since the article was written, so if you're confused by that, you're just missing context, and that's OK.
As for "anti-JWT" arguments, I've made them separately from the argument of Sven's claims. JWT is an error-prone cryptographic design. I wrote a replacement standard called PASETO that doesn't contain these foot-bullets. I still don't recommend people use PASETOs for sessions!
- manigandham 8y agoYes I understand that it's about client vs server managed state and the balance between. You can see this noted in my very first comment. But this article is titled and talks about JWTs at great length with pros and cons, which is completely misleading. The fact that many of the comments here are only talking about JWTs vs cookies and skip over what and where the state is managed only further reflects that confusion. Perhaps a better article should be written and posted.