7 ms·
> "You cannot invalidate individual JWT tokens". Which every time I've implemented, the general guideline is to check for invalidated nonces somewhere. Which re
by jotato 4mo ago
> "You cannot invalidate individual JWT tokens". Which every time I've implemented, the general guideline is to check for invalidated nonces somewhere. Which resolves that random blog posts second point too.
100% agree. This is common sense to me and I'm always surprised to re-learn people don't do this
- hparadiz 4mo agoNot checking the signature on every single JWT is the same as storing a password in plain text.
- Natfan 4mo agoworse, it's storing identities in an editable format that any attacker can use to impersonate any user, no?
- hparadiz 4mo agoEven worse than both of those scenarios. If you don't check the signature anyone can simply write whatever they want in the payload string. The signature is always generated by combining the payload with a private key. Then the receiver uses the public key to verify the signature. If you don't do that the payload can be modified to be anything. Storage not required by the attacker. It's like prompting for a password but accepting any password as valid.