DEV Community

Discussion on: JWT can fit as an authentication system with a blacklist technique

Collapse
 
dagnelies profile image
Arnaud Dagnelies

You also confuse HTTP codes. 403 is when you are authenticated but access to the resource is forbidden because of insufficient rights. When you are logged out, you become 401 Unauthorized.

Collapse
 
irakan profile image
Rakan

Since its a blacklist I choose 403 :)