Does JWT put your web app at risk?
blog.prevoty.com
blog.prevoty.com
the client could simply ignore it. All prior tokens would
still be valid.
No they are not.
Also the same applies to sessions, sessions should be refreshed, too. To clean up, your application may null out the session
or remove the persisted value from the data store. The
result is the same; no more session.
The same with JWT. The data is cryptographically signed with a Hash-based Message
Authentication Code (HMAC)
Not always correct. When you deploy an update to the application and want to invalidate
current sessions? When you’re updating sessions as data changes?
When you’re storing sessions?
The same way you would do with a session. You wouldn't clean your datastore you would change your secret.And still if the session won't get deleted when pressing logout you have the exact same problem.
Also there aren't many users pressing the logout Button anyway.
Edit: Btw. Sessions have flaws. Tokens have flaws, too. However the Flaws the author writes aren't actually problems / flaws it's just FUD.
I think the idea of a user holding onto old expired tokens assumes that the user is a malicious party. A more useful example would be if the token were stolen, so the malicious party would not respect any attempts to expire the token before its expiration time is up.