JWT best practices for max security

  Рет қаралды 7,452

PS After Hours

PS After Hours

Күн бұрын

Support my work / pawelspychalski
Here are a few tips on how to make your JWT tokens more secure. JWT by itself is secure out of the box, but our authentication and authorization policy can benefit if you do the following:
How to revoke a JWT token: • How to revoke a JWT to...
0:00 Let's increase the JWT security level
0:21 Why JWT is safe?
0:46 Keep the issuer of the token private key safe
1:03 Do not put any secrets into the JWT token
1:45 Keep the lifetime of the access and refresh token short
2:51 Not-Before policy
3:22 Use scopes!
4:24 More about JWT tokens
#quadmeup #youtube
If you want to support me:
✅ Patreon / pawelspychalski
✅ Banggood affiliate bit.ly/2P8oAxr
✅ Paypal paypal.me/pawelspychalski
▶ Discord server quadmeup.com/discord
▶ My website quadmeup.com/

Пікірлер: 7
@PSAfterHours
@PSAfterHours 2 жыл бұрын
How to revoke a JWT token: kzfaq.info/get/bejne/oOByZ7eX0rW-qas.html
@heshiebee
@heshiebee Жыл бұрын
Great video, very informative
@matthewrichardson8162
@matthewrichardson8162 Жыл бұрын
Great video!
@jorgeromero4680
@jorgeromero4680 Жыл бұрын
can you use jwt in inav?
@ShibraTai
@ShibraTai 3 ай бұрын
What if the token gets leaked....if a person has the token he/she would be able to hit the api
@imissthestacy4803
@imissthestacy4803 2 ай бұрын
It would indeed be stolen and used to access api but then expired, as a dev you'd better to protect from this theft rather then figuring out how to stop a stolen one, use http only cookies secure https connection
@syffs-sq6bw
@syffs-sq6bw 7 ай бұрын
sorry but either you dont know what you're talking about, or you're omitting the truth? JWT used in an authorization context is a secret, even if it doesn't contain any secret info, as they're used to perform authenticated calls! There's much more to JWT security than what you mention, starting with where they're stored for instance, or how they're generated (fingerprint?) or combined with other security measures.
JWT claims explained: registered, public and private
5:20
PS After Hours
Рет қаралды 4,7 М.
100❤️
00:19
MY💝No War🤝
Рет қаралды 23 МЛН
Зачем он туда залез?
00:25
Vlad Samokatchik
Рет қаралды 2,8 МЛН
Cat Corn?! 🙀 #cat #cute #catlover
00:54
Stocat
Рет қаралды 15 МЛН
#SPLITINTOWORKBOOKS BASED ON COLUMN VALUES
31:12
J A EXCEL
Рет қаралды 6
What Is JWT and Why Should You Use JWT
14:53
Web Dev Simplified
Рет қаралды 1,1 МЛН
Getting API security right - Philippe De Ryck - NDC London 2023
51:49
NDC Conferences
Рет қаралды 26 М.
Difference between cookies, session and tokens
11:53
Valentin Despa
Рет қаралды 602 М.
Cracking JSON Web Tokens
14:34
The Cyber Mentor
Рет қаралды 55 М.
HTTPS, SSL, TLS & Certificate Authority Explained
43:29
Laith Academy
Рет қаралды 77 М.
Why is JWT popular?
5:14
ByteByteGo
Рет қаралды 293 М.
Secure authentication for EVERYTHING! // Authentik
39:50
Christian Lempa
Рет қаралды 133 М.
Зачем ЭТО электрику? #секрет #прибор #энерголикбез
0:56
Александр Мальков
Рет қаралды 619 М.
Отдых для геймера? 😮‍💨 Hiper Engine B50
1:00
Вэйми
Рет қаралды 1,2 МЛН
Здесь упор в процессор
18:02
Рома, Просто Рома
Рет қаралды 371 М.
Top 50 Amazon Prime Day 2024 Deals 🤑 (Updated Hourly!!)
12:37
The Deal Guy
Рет қаралды 1,4 МЛН
Как правильно выключать звук на телефоне?
0:17
Люди.Идеи, общественная организация
Рет қаралды 1,7 МЛН
1$ vs 500$ ВИРТУАЛЬНАЯ РЕАЛЬНОСТЬ !
23:20
GoldenBurst
Рет қаралды 1,8 МЛН