|
|
|
|
|
by the_sleaze9
1360 days ago
|
|
> what damage can that employee do in 5-10 minutes? This is not an authentication issue (JWTs) this is a classic authorization issue (Permissions/Roles). It's not the authentication layer's fault if you allow everyone root access. JWTs are just fine. Bearer tokens are just fine. You can write shitty session code just as easily as shitty OAuth2 code. |
|