4 ms·
Refresh tokens are the real alternative, IMO. I kinda agree it looks like an ad for redis, since it doesn't even considers alternatives.
by ORioN63 5y ago
Refresh tokens are the real alternative, IMO.
I kinda agree it looks like an ad for redis, since it doesn't even considers alternatives.
- allset_ 5y agoAgreed. Long(er) lived refresh tokens, and then having signed access tokens such as JWTs so that the API server doesn't have to hit the database on every request.
- digianarchist 5y agoHasura [0] has a great article on how to make front end authentication as secure as possible. [0] - https://hasura.io/blog/best-practices-of-using-jwt-with-graphql/ https://hasura.io/blog/best-practices-of-using-jwt-with-grap...