Hacker News new | past | comments | ask | show | jobs | submit login

I actually find this post/ad for Redis pretty ironic, because Redis is actually a really great solution for storing revoked tokens (since you can just store the token with an expireat equal to the token's expiry timestamp). I do think it's a serious issue that most jwt howtos don't mention expiring tokens and/or refresh tokens, but "JWTs are not safe" is hilariously hyperbolic.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: