Developers often overuse JWTs, sometimes going as far as storing all the routes that a user should access within them. Mixing the authentication and authorization layers messes up our code. The best way to avoid this is to have the JWT only include the claims and scopes for the user's identity and their relationship within the

9m read timeFrom permit.io
Post cover image
Table of contents
What makes permissions complex?The Antipatterns

Sort: