4 ms·
Performance may be negligible but how is it unsafe?
by bweitzman 11y ago
Performance may be negligible but how is it unsafe?
- nly 11y agoYou can't revoke a token if you have no server-side state to purge. Relying on timeouts is a fairly crude way of going about it.
- bweitzman 11y agoYou can't revoke a singular token but you can change your secret key to revoke every token.
- eloisius 11y agoOr, instead of putting the user id in the claims hash, you could have a separate lookup field on the user model explicitly for finding users by JWT. That way, you can have a "log me out everywhere" button on your site. Not quite as smooth as revoking a single authentication, but better than nothing.