TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

The Case Against Token-Based Authorization

9 点作者 alex-olivier超过 3 年前

2 条评论

detaro超过 3 年前
This seems to confuse terminology a bit. The problem described isn't with using tokens (which is good standard practice), but specifically with using signed tokens and relying purely on the information in them.
robk超过 3 年前
Is that extra database call to get auth status really that costly? Having the client hold any kind of access control is scary to me.
评论 #30146888 未加载