top | item 33022064

(no title)

ryeguy | 3 years ago

This also means an attacker can be running around with a compromised token for up to a half hour before they're stopped.

discuss

order

9dev|3 years ago

If that is unacceptable for the business case, it's probably clear JWTs for sessions are unfit for the particular task?

frankthedog|3 years ago

Is it acceptable for any business to allow accounts to be compromised for a half hour?