3 ms·
"...making it impossible to log users as you can’t invalidate the token for the next hour." I have no idea what you are talking about here, can you explain thi
by blenderdt 4y ago
"...making it impossible to log users as you can’t invalidate the token for the next hour."
I have no idea what you are talking about here, can you explain this?
I work with systems that have a minute expire time. The only issue is that the clocks on all clients should be in sync with the auth server.
- habosa 4y agoI believe they are referring to the fact that most JWT-based auth systems use one-hour token expiry and have no ability to remotely revoke tokens. You can only revoke the user's ability to get the next token. This often leaves a one hour window between when you want the user locked out of your system and when they are practically logged out. The only way I know of to implement instant revocation in a system like this is to keep a blocklist of users/tokens that is constantly checked, which can be slow and removes some of the benefits of JWTs in the first place (that they carry all the auth information you need).
- blenderdt 4y agoAh! Yes this is why we use an expiration of one minute. For us the extra load that the refreshes give is not a problem. Keeping a blocklist seems unnecessary to me, you can just lower the expiration time.