3 ms·
> invites developers to come up with clever explanations and workarounds instead of careful engineering I don't like the accusative tone when talking engineeri
by Autowired 7y ago
> invites developers to come up with clever explanations and workarounds instead of careful engineering
I don't like the accusative tone when talking engineering. There are plenty of good reasons not to use server-side sessions, including the need to replicate them between nodes, or otherwise offload them to an external database, and if you do it asynchronously you have to make your clients sticky. People use JWT to achieve statelessness, which makes it easier to increase availability.
- CiPHPerCoder 7y ago> I don't like the accusative tone when talking engineering. That's fair. I wrote this in 2017 to give a single page arguments against the JOSE standards. The accusative tone is required by the fact that the entire page exists to attack the standard, based on technical arguments. The target audience of the Paragon Initiative blog has always been "PHP developers", and PHP gives you a built-in session mechanism. Which, if you're writing PHP, you should just use. Session security in modern PHP boils down to "use HTTPS". If you're doing some massively distributed system (the likes of a FAANG company project), you can disregard the advice aimed at LAMP stacks.