4 ms·
> JWTs didn't stop us from getting SOC Type I and II certified, or prevent us from getting insurance, not sure what you mean by this. What he probably means is
by AntonCTO 3y ago
> JWTs didn't stop us from getting SOC Type I and II certified, or prevent us from getting insurance, not sure what you mean by this.
What he probably means is that JWT can't be invalidated on its own like you can with a session. But of course it can be done in a similar way, and some products support it. You just lose some of the benefits of JWT. (Let alone the ability to negotiate the logout time span).
- Zetice 3y agoYeah, I just think folks overestimate the value of a "log out of all devices" button. Short TTLs on session tokens seem fine enough for the early months, at least, and then yeah once you can get that first round of funding (or revenue to pay for the lights), getting something like auth0 might make more sense.
- gpjanik 3y agoI agree with you, but that's one of the things that will have to be rewritten if you're in a regulated business - unless you go for some hybrid "JWT but stored in the database" which is, basically, not a JWT.
- SgtBastard 3y agoA JWT with a sid claim that RPs use to check session validity is 100% still a JWT with bearer authz claims.
- gpjanik 3y agoYou can start storing JWTs in the database to regain control over their validity, but then you fundamentally have sessions, just done in an unnecessarily complex way. It goes back to some Xbox vs. Playstation/Android vs. iOS type of argument here, but JWTs _as a stateless token_ (as most people would use them) are just not suitable for the job if you're in a business that requires good security practices. I wrote that point specifically because rewrite of authentication in the middle of product building just to get certified/approved by pentesters is a horrible experience. Using auth0 or Okta or whatever software that handles it for you is probably advised as the person above wrote.