mebrown ([personal profile] mebrown) wrote in [personal profile] mjg59 2022-04-11 04:19 pm (UTC)

Re: Bearer tokens are just awful

You can address this by using the OpenID redirect URL to launch a "normal" session that you can expire, ie. dont use the JWT directly as your 'session'. This is basically what I've done on a couple products and it seems to work well.

You can expire a session with immediate effect, and make the user re-do their oidc login (whereupon you can check the account expiry/etc)

Post a comment in response:

If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org