• bitfucker@programming.dev
      link
      fedilink
      arrow-up
      1
      ·
      2 months ago

      The post already addressed that. JWT do have their place and that’s mainly for server to server handoff with short lived lifespan. After which, the recommendation is using Device Bound Session Cookie