Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

ergo: if it's ok to have an un-revocable insecure session - use JWT tokens.


Or use JWT + OpenID Connect in a centralized mode, as the article explains toward the end.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: