Javascript Others

jwt && remember me functionality

JSON Web Token (JWT) is an open standard (RFC 7519) that defines a compact and self-contained way for securely transmitting information between parties as a JSON object. This information can be verified and trusted because it is digitally signed. JWTs can be signed using a secret (with the HMAC algorithm) or a public/private key pair using RSA or ECDSA.

Although JWTs can be encrypted to also provide secrecy between parties, we will focus on signed tokens. Signed tokens can verify the integrity of the claims contained within it, while encrypted tokens hide those claims from other parties. When tokens are signed using public/private key pairs, the signature also certifies that only the party holding the private key is the one that signed it.

As jwt is stateless frontend session there is no need to store token in back-end side for remember me functionality.

Simply storing/removing jwt in cookie with expiration date works great!

https://jwt.io/introduction/

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *