3 ms·
The argument is that the blacklist is as much a SPOF as a session server would be. The blacklist kills the statelessness.
by NewEntryHN 7y ago
The argument is that the blacklist is as much a SPOF as a session server would be. The blacklist kills the statelessness.
- enraged_camel 7y agoExactly. Even if it's not a SPOF, it becomes yet another piece of architecture you need to worry about distributing and scaling (if you're at the point where JWTs are attractive to you due to their scalability).
- james_s_tayler 7y agoDoes that negate all the benefits though? If a single component of your application maintains a little state, say the API Gateway, and all the downstream services simply get a clean JWT they can trust with all the right claims in it? I'm thinking this is still nicer than having every downstream service also having to check auth claims against some datastore.
- jeltz 7y agoYes, because then the API gateaway could instead just use traditional sessions and attach relevant data when forwarding the request downstream.