3 ms·
I'm not sure I understand the people claiming you should use server side session tokens instead. How am I supposed to make that work with Angular? I have to be
by mooseburger 7y ago
I'm not sure I understand the people claiming you should use server side session tokens instead. How am I supposed to make that work with Angular? I have to be able to send to the client the user privileges somehow.
- jgalentine007 7y agoIt's pretty easy with authentication cookies and csrf tokens. I switched back to sessions too after messing around with jwts for a bit.
- GordonS 7y agoWhen logging in, the backend will generate some state (e.g. user privileges) and store it somewhere, alongside a random session ID. It might be stored on disk, in a database or in a KV store like redis. The backend returns this session ID in a cookie. You store this session ID as a client-side cookie, which gets sent on every request to your backend. When your backend receives a request, it will (typically using some kind of middleware) lookup the session ID in the backing store and deserialise the state. Sliding expiration is typically used, so as long as you keep making requests, you'll remain logged in. Revoking a single session ID is very easy, since you've just deleting a single row/key/line from your backing store.