DEV Community

Discussion on: How security and privacy impacts the database design

Collapse
 
rouilj profile image
John P. Rouillard

Looks like you dropped and entire paragraph:

Same if the user is inactive for too long. Simple, effective and there is not much that can go wrong.

    [umm.....]

There are two dangers with it. First, if the token which is typically stored browser side is stolen, the attacker can impersonate the user, even long after the user signed out... Except if you keep a database of revoked tokens, which not only loses the main benefit of JWT being "stateless" but also adds undesired complexity.
Enter fullscreen mode Exit fullscreen mode
Collapse
 
dagnelies profile image
Arnaud Dagnelies

Oh, thanks for noticing. And for reading it as well ^^. I guess I made some mistake during editing, I'll fix that.