3 ms·
JWTs can totally store state. I've found good use cases for it and I've never understood why people immediately get up in arms about it - possibly conflating th
by spyspy 5y ago
JWTs can totally store state. I've found good use cases for it and I've never understood why people immediately get up in arms about it - possibly conflating the concepts of JWTs themselves and OAuth 2.0. It's just a damned signed json blob. Trying to act like it's anything more is missing the point.
- emaginniss 5y agoThe statelessness being discussed here is about server-side statelessness. It allows you to build a server that gets all the needed information about a transaction from the data being provided (url, body, headers) rather than having to look up authentication information based on a token that the request carries. This is valuable when you want to keep your servers very scalable without relying on a shared data storage mechanism that they must all keep up to date with authentication tokens and data.