56
submitted 1 year ago by [email protected] to c/[email protected]

Right guys?

you are viewing a single comment's thread
view the rest of the comments
[-] [email protected] 1 points 1 year ago

Once a token is issued it is valid until it experies. There is no way to disable a token short of changing the secret used to sign them which would invalidate all existing tokens for all users.

[-] [email protected] 3 points 1 year ago

I actually suggested exactly that elsewhere. It would be a nuclear option, for sure. Since it would require every single user to log back in. But it would 100% without a doubt stop the attacker in their tracks.

[-] [email protected] 1 points 1 year ago

That's bad design because you can bind a user token to a per-account value which can be rotated to deprecate tokens

this post was submitted on 10 Jul 2023
56 points (96.7% liked)

lemmy.ml meta

1408 readers
20 users here now

Anything about the lemmy.ml instance and its moderation.

For discussion about the Lemmy software project, go to [email protected].

founded 3 years ago
MODERATORS