DEV Community

Discussion on: Using JWT Token/Cookie based session authentication — Potential Identity Theft & Data Exploitation

Collapse
 
adimb profile image
Adi Mor Barak

You send your session id or token, if it's JWT token it can be decrypt any why... the only information you usually store is your user id, client id, user role - this info means nothing but you get a extra security layer that helps you mitigate this vulnerability