3 ms·
There is a much more straightforward way to handle session expiry not mentioned in the article: in most cases your application will need to get something like a
by speleding 5y ago
There is a much more straightforward way to handle session expiry not mentioned in the article: in most cases your application will need to get something like a "User" object from the database. That object can simply contain a version number that you increase when you need to log someone out. If the version number in the session does not match the one in the JWT you discard it.