4 ms·
Yes, it is good if you can avoid checks, and in most cases you can. But in practice it doesn't matter very much: - Scaling is rarely the problem. I never experi
by AntonCTO 3y ago
Yes, it is good if you can avoid checks, and in most cases you can. But in practice it doesn't matter very much:
- Scaling is rarely the problem. I never experienced it myself. The same goes for the session.
- The complexity can be hidden behind a library. Iirc there is even a specification for this.
- You have other advantages because you usually use JWT with OAuth2.x/OIDC in the SSO context.
- You benefit from standardization.
CRL is probably not going to help you. At least I have no idea. But jti's blacklist will. Don't forget - you still have to maintain and distribute it, which probably won't lead to a better implementation.
- preseinger 3y agoscaling auth infra is basically the entire motivation for things like JWTs if you don't care about every request making an auth check, that's great! then just use basic sessions or whatever. there's no reason to use anything more complex