> JWT Tokens
> Cons: Susceptible to token theft (e.g., XSS attacks) if not handled carefully. Must be short-lived or use refresh tokens.
>
> Session Tokens
> Pros: Generally more secure as they rely on server-side storage, mitigating issues like token theft.
>
> Cons: Vulnerable to CSRF attacks if not handled properly.
Isn’t session token theft as much of an issue as JWT token theft? Why is there a difference in security just because in one case it’s a JSON blob that says user_id:4,is_admin:false and in the other it’s an opaque string? Surely session tokens are equally vulnerable to XSS as JWT tokens?
The author then claims that JWT are “potentially faster since no server-side lookup is required. However, JWTs can be large in size”. How large? How does it affect things? Does it affect request latency, or server time decoding the JSON? The comparison with session tokens is then made: “server-side lookup, which can introduce latency, especially with a high number of active sessions”. Where is the latency introduced? Because an RDBMS is slower when there’s many rows in the session table? Because Redis can’t do an efficient GET?
This article is a whole bunch of vague trueisms. The author clearly knows some stuff about it, but isn’t able to articulate it well enough to help the reader make a good decision or walk away better informed than having not read it.
It almost feels cargo culty.
Edit: could we finally get proper quoting support?