Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

JWTs - Patterns and Anti-patterns in Authentication

LASCON via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk examines nuanced JWT use cases and anti-patterns, covering cookies, sessions, signing secrets and algorithms, expiration, revocation, refresh and access tokens, key rotation, and service-to-service authentication. It also discusses trusted libraries, Macaroons, and when not to use JWTs for sessions.

Syllabus

Intro
Speaker: David Gilman
HTTP Cookie
Stateless Tokens
Server Side Session
Clifford Stoll's Chocolate Chip Cookie Recipe
Trying to be Everything to Everybody
JWTs as Sessions
Attaching with JavaScript
Weak HMAC Secrets
No Revocation
No Expiration
Database for Revocation
Refresh + Access Tokens
Fragile Built-In Signing Key Rotation
Fully Stateful
Multiple Overlapping Implementations
Service 2 Service Auth
Shared Token
Auth Service
Revocation via Cache
Hardcoded Algorithm
Use Alternatives
Use Trusted Libraries
Registered Claims
Macaroons Paper
Stop Using JWT for Sessions

Taught by

LASCON

Reviews

Start your review of JWTs - Patterns and Anti-patterns in Authentication

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.