DEV Community

Discussion on: Be careful of the JWT hype train

Collapse
 
dangolant profile image
Daniel Golant

No role changes or payment status changes might have occurred since the JWT was issued?

Can't we revoke JWT in that case?

By no means a JWT advocate btw.

Collapse
 
madhadron profile image
Fred Ross

Then you have a stateful revocation list you have to make available to every server and JWT is no longer stateless.

Collapse
 
dangolant profile image
Daniel Golant

Oh right, didn't think of that.