Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you checking the session on the server, you might as well just use a token in a cookie. The point of the JWT complexity is to avoid that.


JWT tokens being passed via cookies is a valid use case.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: