TE
TechEcho
Home
24h Top
Newest
Best
Ask
Show
Jobs
English
GitHub
Twitter
Home
The Case Against Token-Based Authorization
9 points
by
alex-olivier
over 3 years ago
2 comments
detaro
over 3 years ago
This seems to confuse terminology a bit. The problem described isn't with using tokens (which is good standard practice), but specifically with using signed tokens and relying purely on the information in them.
robk
over 3 years ago
Collapse
Is that extra database call to get auth status really that costly? Having the client hold any kind of access control is scary to me.
评论 #30146888 未加载