3 ms·
It calls some of these stateless, but don't they all have to run a secondary look-up? For example, in Basic Authentication, you still have to check the usernam
by combatentropy 6y ago
It calls some of these stateless, but don't they all have to run a secondary look-up?
For example, in Basic Authentication, you still have to check the username and password against a database, whether that be a file, a relational database, LDAP, etc. For JWT, to verify the signature you must look up the issuer's pre-shared or public key.
Is it even possible for a request be stateless if it requires authentication?
- Shmebulock 6y agoI agree the article is confusing wrt state. Basic Auth is stateless on the client side but not on the server side. Token auth is stateless on server side; it does not need to store any more public/private key pairs as the number of authenticating users increases. It can just use one. So authenticating users does not affect state
- combatentropy 6y ago> it does not need to store any more public/private key pairs as the number of authenticating users increases That's a good point. Thank you