A Report on the Flawed 2016 Democratic Primaries 10 years ago
This is unacceptable. How can you be proud of cheating to win?
HN user
This is unacceptable. How can you be proud of cheating to win?
Even with the exp claim if the user saves the token before they log out they can reuse it until it actually expires, you have to generate jtis and store them in a blacklist which is what the author of the article meant (you still have to have the concept of a session on the server to be totally sure).
Why can't you just change the secret on the server? It would invalidate all sessions.