Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
0 points
LanceH
8y ago
0 comments
Save
Share
How do you revoke access to that token?
0 comments
3 comments · 1 top-level
top
newest
oldest
oxymoron
8y ago
· 2 in thread
Well, you don’t, so if that’s a requirement you’ve got to do it some other way.
e12e
8y ago
You can rotate the secret to invalidate all tokens.
tptacek
8y ago
No, you can't. That breaks all of your users, and so you'll rarely do it, even when it might be warranted. Don't engineer security countermeasures that you (a) might need to rely on and (b) will be afraid to use.
1 more reply
j
/
k
navigate · click thread line to collapse