Where communities thrive


  • Join over 1.5M+ people
  • Join over 100K+ communities
  • Free without limits
  • Create your own community
People
Repo info
Activity
    Lihai Ben-Haim
    @lihaibh
    what if someone could somehow crack a single jwt token of a user (using MITM for example)
    from now on, basically even if the user changes his password, the cracked JWT is already obtained
    lets say the secret private key is kept in the server and never replaced
    that means that once someone get the JWT token he will get access to the user's resources forever
    in session system, we are using a randomly generated id, so even if someone gets the sessionid, the system can somehow recover from it, deleting the sessions, generating new ones etc..
    Tasos Soukoulis
    @taosx
    Is it possible to roll my own jwt authentication on top of oauth2 ? Ex. Create user account using google/facebook oauth2 and then keep authentication using the jwt created by my server?
    Or it's wasteful?
    Ranie Santos
    @raniesantos

    Is it okay or is it a bad idea to add 'remember me' functionality when using JWT instead of sessions?

    I have a project using JWT and I've gotten it to work so far (expires every hour, can be refreshed up to 2 weeks). But right now I have a useless remember me checkbox on my login page.

    I'm trying to decide whether I should remove it or make it functional.

    I've been looking through the code and it seems refresh_ttl isn't found in any of the token's claims.

    The exp claim only refers to the regular ttl.

    So I can't use the getJWTCustomClaims method in the User model specified in the docs of the package.

    this place is a ghost town
    niluroy
    @niluroy
    Hey guys
    jwt.verify(token, config.secret, function(err, decoded){})
    Here decoded is returning me id, iat and exp. So, what is iat?
    Ranie Santos
    @raniesantos
    iat means Issued At
    Javier Aviles
    @javieraviles

    Hi! I wanted to leave here a good boilerplate with Koa2 Typescript, jwt-auth, logging orm sql docker.... Very good Readme, hope it helps somebody!

    https://github.com/javieraviles/node-typescript-koa-rest

    Nastaran Heydari
    @noonhe
    Hi! How can I add Authoization : Bearer <token> to my request header in my code (not in postman)?
    Boris Pavlov
    @bpavlov
    I have a question about the refresh token
    Boris Pavlov
    @bpavlov
    I want to use JWT in order to reduce database requests. Unfortunately that way I am not able to temporary "disable" users. Even more if my jwt access token TTL is 5 min after 6 min mark I will have to re-authenticate.
    What is the best way to solve this issue?
    Dilip Kumar
    @dilipjnu_twitter
    hi
    Adeshina Hammed H.
    @D-sense
    @noonhe , you can achieve that by using the header in the curl (if you’re using CURL.
    Naguib Ihab (A.K.A. Nick)
    @naguibIhab_twitter
    flihub
    @flihub
    anyone here?
    BatunaAz
    @BatunaAz
    i installed jwt framework using composer require web-token/jwt-framework. But my server directory have not // use Jose\Component\Core\JWK;
    // use Jose\Easy\Build; these directories. What's wrong guys. Sorry i am beginner. Thanks
    Srikar Rao Gandla
    @srikarrao
    Hello, I'm new to JWT tokens security. Wanted to know who generates the signing key? is it the server or signing key is nothing but user's password? Thank you!
    Mario N Junior
    @manjunior

    Hi guys, hope you all are well.

    I'm having a problem with my Laravel 8 API using the latest version of the Tymon\JWTAuth lib.

    My Laravel Api has some protected routes, but I don't login to it to get the token. For that I log into an external API, get the generated token and send this token to my Laravel api. To validate the token I get from the external API, I set the JWT_SECRET key from the .env with the same key as the external API.

    Does that solve the problem? Is it otherwise? Can anyone tell me where to go?

    Below is my middleware to verify the token of each request when the route is protected.

    `
    public function handle(Request $request, Closure $next)
    {
    try {
    $user = JWTAuth::parseToken()->authenticate();
    } catch(Exception $err) {
    if ($err instanceof \Tymon\JWTAuth\Exceptions\TokenExpiredException) {
    return response()->json(['status' => 'Token is Expired'], 401);
    } else if ($err instanceof \Tymon\JWTAuth\Exceptions\TokenInvalidException) {
    return response()->json(['status' => 'Token is Invalid'], 403);
    } else {
    return response()->json(['status' => 'Authorization Token not found'], 404);
    }
    }

        return $next($request);
    }

    `

    Denys Finchenko
    @dfinchenko
    Hi! How can I generate just JWT token with custom data without user credentials in laravel?