|
|
|
|
|
by sytringy05
2934 days ago
|
|
Everybody is doing it (at least where I'm from). There's good framework/vendor support for OAuth 2 and JWT breaks the nexus between the services and the magic auth server that must be called on each and every request. Even with the horrors of the implementation ({"alg": "none"}) It's a risk that many organisations are willing to take. |
|
But tptacek seems to be saying 'I want you to understand all this S2S stuff before I can begin to rant at you about JWT'. That's a bit different and I'd like to get the rest of this newsletter.