4 ms·
My toy projects I include the IP address in the JWT payload, so JWT is only good for that IP. I don't always see that in examples. Not sure any downsides of th
by dpweb 4y ago
My toy projects I include the IP address in the JWT payload, so JWT is only good for that IP. I don't always see that in examples. Not sure any downsides of that
(if client is rotating IPs or VPN I may be blocking them anyway). But seems consistent with cookie concept that a login is only good on that device.
I think its a debate. I like to keep the db clean of sessions but easy enough to keep in server memory if I down the server I don't mind making people login again.
- hasperdi 4y agoIt's a bad idea... Users on mobile or use cellular connections get their IPs rotated often. There's also CGNAT (Carrier Grade NAT), users share a pool of IPs.
- resoluteteeth 4y agoIt's not realistic in 2022 to assume that ip addresses won't change during sessions. That's why virtually no sites do this