Lesson 3.18mIntermediate9.2k students
Sessions versus JWTs
Server sessions are revocable; JWTs are stateless and awkward to revoke. Pick based on whether you need to log someone out immediately.
This lesson sits in Authentication Done Right, part of Practical Web Security. It assumes what came before it and leads directly into the next lesson in the module.
In this lesson you will
- Compare revocability and statelessness honestly
- Store tokens in cookies with the right flags
- Design refresh and logout before you ship
Resources
Your notes for this lesson will appear here.