5 ms·
> It seems like very little effort to implement this yourself in a way that doesn't involve completely trusting a different company. What about cookie configur
by tompic823 6y ago
> It seems like very little effort to implement this yourself in a way that doesn't involve completely trusting a different company.
What about cookie configuration (secure, httpOnly, samesite), signing, expiration, session management, etc? Getting and setting the cookie value are the easy part.
For someone entrenched in appsec, most of these are fairly easy. But most developers are not entrenched in appsec. For proof of this, look at the popularity of Auth0.
- rishabhpoddar 6y agoThanks! And more proof for this comment is the sheer number of questions / blog posts written about sessions and JWTs almost weekly on reddit, HN, stackoverflow etc.. If this was very simple to solve, securely, those questions, blog posts would not exist.