4 ms·
> The other big mistake I've seen is encoding personal data in the token, You’re right that this is a big mistake but I also thought this was in fact one of th
by statictype 6y ago
> The other big mistake I've seen is encoding personal data in the token,
You’re right that this is a big mistake but I also thought this was in fact one of the primary allures of JWT - an attempt (misguided) to make session management stateless and avoid that database roundtrip on the server end?
- jimktrains2 6y agoThis has been my experience, and the issue of figuring out if a token has been revoked is usually punted on.