Global Feed Post Login
Replying to Avatar ghost of mordoria

honestly, this all makes it sound like JWTs are horrible

except for the stateless authorization thing (which no one uses, everybody ends up calling the mother service anyway because they are unable to verify the signature by themselves and they don't even know the pubkey of the mother service either, that is not made available nor clear anywhere) everything else is just worse for all sides

Avatar
Tim Bouma 5mo ago

Yeah. I’ve concluded that OAuth is broken beyond repair but someone said that JWT fixes that.

Reply to this note

Please Login to reply.

Discussion

Avatar
ghost of mordoria 5mo ago

jwt is often used for the token that oauth yields

Thread collapsed