3 ms·
On the first point what’s stopping a bad actor that found the key in the source code from faking those headers? As for having to ‘wrap’ third-party services th
by somada141 7y ago
On the first point what’s stopping a bad actor that found the key in the source code from faking those headers?
As for having to ‘wrap’ third-party services that seems like a cumbersome solution.
I guess one way to go would be to use an API gateway like Kong [0] which supports JWT validation out of the box but performance-wise I always found Nginx to be superior.
[0] https://konghq.com/kong https://konghq.com/kong