ErrorDodo / ErrorDodo/CNCStorageV2

Assign tokens into a database so they can be revoked on hacked account

Open
#1 0 comments 0 reactions 0 assignees View on GitHub
enhancement question
Dominant language
Rust
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Description

Currently we are using stateless JWTs and JWT Refresh tokens.

The way they are currently planned to be revoked is by sending a response to the client saying "Delete tokens" and the web client will delete it from the cookies/state

Should we instead be saving tokens to a database this way we can just revoke them by deleting the records of the tokens?

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.