Похожие чаты

How to I handle user authentication in microservice pattern? I have

auth service which is will signin user and send a jwt to the client. I have set an expiration time of 5 mins. Now there is also a refresh token generated which is of 3 months. Now i send these both to the client. Whenever I make a request to other service, I can only check if the token is valid or not. That was fine until I realized that a user can be banned by admin, and till 5 mins, their token will remain valid. How do I handle this?

2 ответов

3 просмотра

some people in internet show a way to solve this with a invalidation list, but that makes the jwt almost useless and breaks the design

You need to have a blacklist that will be checked against when user connect. That blacklist is controlled by admin. Or have some revocation mechanism that will revoke whatever token you have locally that will be used to verify the authentication

Похожие вопросы

Обсуждают сегодня

А чем вам питонисты не угодили?😂
.
79
or any website to buy prepaid card with xmr that's not trocador that's down?
Umbrella Party Partner
18
Всем привет, написал код ниже, но он выдает сегфолт, в чем причина? #include <stdio.h> #include <stdlib.h> #include <string.h> struct product { char *name; float price; };...
buzz базз
75
Hi, I can't understand promises in JavaScript and what we should use them for (maybe the teacher didn't teach well XD). Do you have a solution for this? And are promises used...
A
29
Ещё такой вопрос. Мне необходимо хранить пароль пользователя локально. Для этого планирую использовать ini файл. Это для автозаполнения полей логин и пароль при авторизации. Е...
Евгений
19
Ты просто гитлеровскую эстетику плохо понимаешь. Он же всё под Цезаря делал. А это как бы запрещённый приём в политике. Пиджаки они зачем все носят? Чтобы показать что они тип...
Ivan Kropotkin
4
Xem delist ho rha hai agr naa bhechu toh kya hoga after 1 july?
ABHI
27
i need usdt exchanged to xmr without kyc any site there ?
Certained
12
Did you guys see the latest tweet from TonGifts? 🚀
Mike
44
Regarding your hive account, the keys haven’t been changed so, I’d ask on the Leo discord if they can help. You’re using the private keys specifically, not public right? (Pub...
Grapthar - Splinterlands Team
5
Карта сайта