| ▲ | skhameneh 3 hours ago | |
Other commenters are suggesting you can’t blame the spec for end implementation mistakes, except that’s one of the many issues - JWT being so error-prone is a problem. I use JWT just for handling of tokens, because it’s so well supported, but I won’t use it for anything more than token storage _because_ it is so vulnerable to mistakes. The fact that mistakes are so easy to make is indicative of poor design in the spec itself. | ||