3 ms·
We don't use JWTs because we think we're google scale, we use them because they're kinda cool. Cheap, stateless auth across services is really handy. If I rolle
by menacingly 2y ago
We don't use JWTs because we think we're google scale, we use them because they're kinda cool. Cheap, stateless auth across services is really handy. If I rolled my own solution, it would just look like a shitty jwt.
There are definitely arguments to me made against ridiculous over-engineering, modern web dev has taken the problems of 1% of engineers and made them problems for 100% of engineers, but I think this is a bit of a silly one to focus on
- j16sdiz 2y agoWe don't use JWT because we are NOT google scale. A centralized database for sessions, and we can extend/revoke any token anytime.
- rezonant 2y agoWhat's interesting about this argument is that nothing is stopping you from doing this same thing using JWTs. Just generate your token and store it as a claim in the JWT. You can check the revocation of the stored token without even validating that the token is genuine, if that is fortuitous. What this buys you is the ability to attach clear text information with the token, and, if you are doing asymmetric validation, the ability to validate both the security credential and the included plaintext information in an untrusted (client side) setting.
- menacingly 2y agoI actually think the revocation argument is the over-engineering case here. I'd argue that people who need to avoid hitting their database on every request outnumber people who need sub-minute revocation
- hot_gril 2y agoI don't see how this solution means you cannot use JWTs.