3 ms·
All such tokens would be effectively revoked anyway since you check the iat timestamp (or lack thereof) at the authorization point.
by alboy 7y ago
All such tokens would be effectively revoked anyway since you check the iat timestamp (or lack thereof) at the authorization point.
- jacobr1 7y agoYep, and that is what we do. But we also check to ensure that a secure cipher was used, not none. Many of the "JWT is insecure" type articles (and real vulnerabilities found) were based on the fact that people just used dumb defaults and didn't secure things. So the argument is really that JWT is a footgun without some adult supervision.