Y
Hacker News
new
|
ask
|
show
|
jobs
by
Rapzid
45 days ago
Yeah, hasn't it been "best practice" for a decade or more to treat JWT like a ticket and swap it for a cookie-based session ID in anything browser-like? Then you just do all the cookie session "best practices" to lock it down.