Knowledgebase

Understanding Tokens and Sessions Print

  • 0

What a token actually carries.

WHAT AN OPAQUE TOKEN IS

A random string meaning nothing by itself.

HOW IT IS VALIDATED

By looking it up.

WHAT THAT PROVIDES

Instant revocation.

WHAT IT COSTS

A lookup on every request.

WHAT A SIGNED TOKEN IS

One containing claims, with a signature proving it was issued by someone trusted.

WHAT THAT PROVIDES

Validation without a lookup.

WHAT IT COSTS

Revocation becomes difficult.

WHY

A valid signature remains valid until expiry, whatever has happened since.

WHAT TO DO ABOUT THAT

Keep lifetimes short Maintain a revocation list for the exceptional cases

WHAT SIGNED TOKENS MUST BE CHECKED FOR

A valid signature An expected issuer An expected audience Not expired

WHAT THE CLASSIC MISTAKE IS

Accepting a token that declares its own algorithm as none.

WHY THAT IS CATASTROPHIC

Anyone can then forge a token.

WHAT TO DO

Specify the expected algorithm, and reject anything else.

WHAT TO NEVER PUT IN A SIGNED TOKEN

Anything sensitive.

WHY

The contents are readable by anyone holding it.

WHAT SIGNING PROVES

Integrity, not confidentiality.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot