3 ms·
What you describe sounds like it will make any explicit log out action users do on any device turn into a ”log me out from all devices” action, which was probab
by fmbb 1y ago
What you describe sounds like it will make any explicit log out action users do on any device turn into a ”log me out from all devices” action, which was probably not at all the user’s intent unless that is the only explicit option you give them.
- littlecranky67 1y agoA "logout" action from the user should just delete the JWT from the device he is using. Asuming the token wasn't compromised, there is no backend work involved. Is this as secure as doing a blacklist for non-expired tokens? No, it isn't. It is a sane tradeoff between decent security and implementation complexity.
- orphea 1y ago> A "logout" action from the user should just delete the JWT from the device he is using. I wouldn't say should. It may. If you're fine with inability to terminate sessions on other devices.
- littlecranky67 1y agoTerminating sessions on other devices is not possible, but another tradeoff is using a "Logout from all devices" mechanism. In that case you just have a global "token not issue before" field, and when you logout from all devices, set that timestamp to the current time (and all issued tokens will fail authentication). But again, tradeoff. You individual requirements may vary.