TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Let's stop arguing about JWTs and just fix them

5 pointsby colinclerkover 2 years ago

1 comment

Nextgridover 2 years ago
I disagree. Just because a subpar implementation is &quot;winning&quot; thanks to cargo-cult developers doesn&#x27;t mean it&#x27;s time to put up with mediocrity especially in a security context where a failure can be disastrous.<p>If you have a business case for JWTs, fine, take on the extra complexity and implement JWTs properly.<p>If you don&#x27;t (and as the author points out, the majority of implementations don&#x27;t need them), push back and do it properly using a simpler system, rather than implement the complexity just to then abstract it away.
评论 #33103591 未加载