3 ms·
JWTs give you a really lightweight auth token. You don't need to store any state on the server, you don't need to do any encryption/decryption to verify them, y
by bweitzman 11y ago
JWTs give you a really lightweight auth token. You don't need to store any state on the server, you don't need to do any encryption/decryption to verify them, you just verify them by hashing. Plus there are all sorts of extensions to the JWT spec for things like timeouts, etc. Plus, the payload is usable by the client, so for example, you're authentication might consist of just sending the user a signed version of the user id or other information that they can use with the API
- nly 11y agoThe lack of server-side auth state only worsens security, and negligible from a performance perspective for common webapps when you're often touching the database anyway (it seems to me you'd really need all your static caches to classify requests and inspect tokens to make this worthwhile).
- bweitzman 11y agoPerformance may be negligible but how is it unsafe?
- nly 11y agoYou can't revoke a token if you have no server-side state to purge. Relying on timeouts is a fairly crude way of going about it.
- bweitzman 11y agoYou can't revoke a singular token but you can change your secret key to revoke every token.
- eloisius 11y agoOr, instead of putting the user id in the claims hash, you could have a separate lookup field on the user model explicitly for finding users by JWT. That way, you can have a "log me out everywhere" button on your site. Not quite as smooth as revoking a single authentication, but better than nothing.
- andreasklinger 11y agojwt's are also useful if "database queries" are expensive (ex distributed systems/webservices etc)