4 ms·
You can start storing JWTs in the database to regain control over their validity, but then you fundamentally have sessions, just done in an unnecessarily comple
by gpjanik 3y ago
You can start storing JWTs in the database to regain control over their validity, but then you fundamentally have sessions, just done in an unnecessarily complex way. It goes back to some Xbox vs. Playstation/Android vs. iOS type of argument here, but JWTs _as a stateless token_ (as most people would use them) are just not suitable for the job if you're in a business that requires good security practices.
I wrote that point specifically because rewrite of authentication in the middle of product building just to get certified/approved by pentesters is a horrible experience. Using auth0 or Okta or whatever software that handles it for you is probably advised as the person above wrote.