4 ms·
I don't really get the point of JWT these days with SameSite and CSP-headers available. And from the backend perspective, most frameworks have session tracking
by TheChaplain 1y ago
I don't really get the point of JWT these days with SameSite and CSP-headers available.
And from the backend perspective, most frameworks have session tracking built-in with cookies so it's super easy to dismiss one or all clients.
With JWT however, that rarely exist and you need to re-implement the whole session-shebang in order to keep track of the clients.
- littlecranky67 1y agoSamesite/CSP Headers and JWT are orthogonal to each other. I use a JWT system for authenticating my SPA against the REST backend, but store the JWT in a cookie (using SameSite=strict and HttpOnly).
- unit149 1y ago[dead]