35 ms·
Man I'm not sure I agree with that. Blowing up a bunch of your clients that rely on your services randomly because one account was compromised is not acceptable
by TheFiend7 7y ago
Man I'm not sure I agree with that. Blowing up a bunch of your clients that rely on your services randomly because one account was compromised is not acceptable for really any professional business regardless of the number of clients.
- JMTQp8lwXL 7y ago"Blowing them up" is a mischaracterization of the situation. You are not mutating their data. You're only asking them to login again.
- SkyPuncher 7y agoActually blowing them up is a completely appropriate description if you have any non-human's relying on JWTs.
- onion2k 7y agoApplications that use authenticated services need to handle being the authentication being revoked. That's fairly obvious regardless of how it happens. If your app doesn't then it's broken.