What a token actually carries.
WHAT AN OPAQUE TOKEN IS
A random string meaning nothing by itself.
HOW IT IS VALIDATED
By looking it up.
WHAT THAT PROVIDES
Instant revocation.
WHAT IT COSTS
A lookup on every request.
WHAT A SIGNED TOKEN IS
One containing claims, with a signature proving it was issued by someone trusted.
WHAT THAT PROVIDES
Validation without a lookup.
WHAT IT COSTS
Revocation becomes difficult.
WHY
A valid signature remains valid until expiry, whatever has happened since.
WHAT TO DO ABOUT THAT
Keep lifetimes short Maintain a revocation list for the exceptional cases
WHAT SIGNED TOKENS MUST BE CHECKED FOR
A valid signature An expected issuer An expected audience Not expired
WHAT THE CLASSIC MISTAKE IS
Accepting a token that declares its own algorithm as none.
WHY THAT IS CATASTROPHIC
Anyone can then forge a token.
WHAT TO DO
Specify the expected algorithm, and reject anything else.
WHAT TO NEVER PUT IN A SIGNED TOKEN
Anything sensitive.
WHY
The contents are readable by anyone holding it.
WHAT SIGNING PROVES
Integrity, not confidentiality.