Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
0 points
remram
5y ago
0 comments
Save
Share
In this context, this would just prevent everybody from logging in. The JWT would correctly get rejected but people would still be getting the wrong token from the CDN over and over.
0 comments
1 comments · 1 top-level
top
newest
oldest
iratewizard
5y ago
Which would you rather? The situation you just described or users accidentally spoofing each other's session?
j
/
k
navigate · click thread line to collapse