|
|
|
|
|
by mrighele
3325 days ago
|
|
In some way he addresses that towards the end: > It's important to note that my experiment is not JWT. > When you reduce JWT to a thing that is secure, > you give up the "algorithm agility" that is a proud part > of the specification. I don't agree with him though, unless the standard requires to implement all of the available algorithms, one may choose to implement only those that he/she deems safe/worth. |
|
Agreed. I view this flexibility as a developer feature, not a client feature.