Похожие чаты

How to I handle user authentication in microservice pattern? I have

auth service which is will signin user and send a jwt to the client. I have set an expiration time of 5 mins. Now there is also a refresh token generated which is of 3 months. Now i send these both to the client. Whenever I make a request to other service, I can only check if the token is valid or not. That was fine until I realized that a user can be banned by admin, and till 5 mins, their token will remain valid. How do I handle this?

2 ответов

9 просмотров

some people in internet show a way to solve this with a invalidation list, but that makes the jwt almost useless and breaks the design

You need to have a blacklist that will be checked against when user connect. That blacklist is controlled by admin. Or have some revocation mechanism that will revoke whatever token you have locally that will be used to verify the authentication

Похожие вопросы

Обсуждают сегодня

Господа, а что сейчас вообще с рынком труда на делфи происходит? Какова ситуация?
Rꙮman Yankꙮvsky
29
А вообще, что может смущать в самой Julia - бы сказал, что нет единого стандартного подхода по многим моментам, поэтому многое выглядит как "хаки" и произвол. Короче говоря, с...
Viktor G.
2
@Benzenoid can you tell me the easiest, and safest way to bu.y HEX now?
Živa Žena
20
This is a question from my wife who make a fortune with memes 😂😂 About the Migration and Tokens: 1. How will the old tokens be migrated to the new $LGCYX network? What is th...
🍿 °anton°
2
30500 за редактор? )
Владимир
47
а через ESC-код ?
Alexey Kulakov
29
What is the Dex situation? Agora team started with the Pnetwork for their dex which helped them both with integration. It’s completed but as you can see from the Pnetwork ann...
Ben
1
Гайс, вопрос для разносторонее развитых: читаю стрим с юарта, нада выделять с него фреймы с определенной структурой, если ли чо готовое, или долбаться с ринг буффером? нада у...
Vitaly
9
Anyone knows where there are some instructions or discort about failed bridge transactions ?
Jochem
21
@lozuk how do I get my phex copies of my ehex from a atomic wallet, to move to my rabby?
Justfrontin 👀
11
Карта сайта