3 ms·
I'm unconvinced of the author's actual understanding of common JWT usage. Suppose you use Azure. You may have one or more app registrations with defined roles
by 4star3star 2y ago
I'm unconvinced of the author's actual understanding of common JWT usage.
Suppose you use Azure. You may have one or more app registrations with defined roles as well as apis exposed within the Azure config. It's convenient to acquire an access token that can be sent to various apis, each of which can accept the token without having to worry about session state or really anything to do with authentication other than validating the token's legitimacy. If I wanted to roll my own security, maybe JWT isn't how I would choose to do it, but I definitely don't want to do that.