|
|
|
|
|
by MaxBarraclough
2480 days ago
|
|
Depending on exactly what we're doing, we can work around this with crypto, right? A token can securely prove that it was issued by the server/service, and under what conditions, without the server/service statefully tracking the token after issuing it. I know I'm not the first to think of this, but I'm not sure how widely used this sort of technique is in practice. |
|