|
|
|
|
|
by gorgonian
2314 days ago
|
|
I did exactly this on the last implementation of JWT I did. Common actions wouldn’t hit the database if the token was less than an hour old, but actions like changing email address or password would always check the database. |
|
The token includes the time when it was created (iat attribute) so critical actions could check that the token is less than 3 minutes old.