3 ms·
Without offering an alternative solution I'm not sure what your co-workers are trying to accomplish. The article doesn't offer much of a solution either. The
by ryan-allen 5y ago
Without offering an alternative solution I'm not sure what your co-workers are trying to accomplish.
The article doesn't offer much of a solution either.
The only valid criticism I see in these threads are unless you are tracking a revoke list then the JWT is still valid on a user initiated logout until it expires.
If you're going to roll your own tokens you're probably going to end up some form of tamper proof encryption even if you're storing additional session information on the backend.
Without specific comparison to other styles of session management this is just all FUD to me.