Hacker News new | ask | show | jobs
by Arch-TK 750 days ago
It's super common to see websites which don't properly invalidate sessions because they use JWTs without tracking them anywhere.