3 ms·
Same story for any session token that isn't rotated on every request. And even then, if they get the latest one you're out of luck. Unless you mean blacklistin
by karatestomp 6y ago
Same story for any session token that isn't rotated on every request. And even then, if they get the latest one you're out of luck.
Unless you mean blacklisting tokens, then, yes, you do need to check your blacklist, though fanning that out to an edge cache should suffice and keep you from needing to hit your authentication service or database every request. But that's true for any long-lived session token.
- jakelazaroff 6y agoThe point is that with stateless authentication, you can’t revoke tokens. If a JWT gets compromise, you need to either wait for it to expire or log all users out by rotating the signing key. With stateful authentication, solving this is trivial: just check your tokens/sessions/whatever against a centralized database every request.