logoalt Hacker News

jotatoyesterday at 6:52 PM1 replyview on HN

> "You cannot invalidate individual JWT tokens". Which every time I've implemented, the general guideline is to check for invalidated nonces somewhere. Which resolves that random blog posts second point too.

100% agree. This is common sense to me and I'm always surprised to re-learn people don't do this


Replies

hparadizyesterday at 7:12 PM

Not checking the signature on every single JWT is the same as storing a password in plain text.