you can encode token version in jwt, start with 1 and increment every time your token is being reneved, store that token version in db and compare in auth middleware and even if someone stoles token, it won't work if you get new one despite old one has not expired
2026-02-06 19:39:58
1
⃟ :
refresh tokens?
2026-02-06 17:35:38
1
Thanon :
is by crypt or argon better?
2026-02-06 08:09:25
0
jari :
Use passportJS
2026-02-07 13:18:57
0
clickprof :
Why JWT and not Opaque ?
2026-02-08 11:12:57
0
hectic :
great security
2026-02-07 06:41:27
0
fred :
cookie, jti, rtr 😁
2026-02-06 18:44:45
0
Forensic Pathologist🩺 :
this is nice
2026-02-05 22:07:53
0
Hirun_D :
usually we go for mongo pre save to hash password
2026-02-06 04:14:44
0
MR. HALL :
Bro do you have any startup in mind.
2026-02-04 10:39:10
0
realsofo :
use salt for password hashing
2026-02-07 13:25:44
0
Dj Redflame :
First don’t use becrypt use Argon2id, second don’t use JWT use session cookies 🙃
2026-02-10 07:48:11
0
Thomas 🇵🇹 :
you need refresh token
2026-02-10 12:14:19
0
To see more videos from user @theforeverknights, please go to the Tikwm
homepage.