Hacker News new | ask | show | jobs
by TobiasA 2384 days ago
Which headaches would that be?
2 comments

That you have to keep a white/blacklist if you want to revoke a token.
Blacklisting is only half the problem. Trying to emulate the same UX of regular sessions (staying logged-in etc) is the bigger pain point.