Skip to content

[Question] JWT and Stateful #1344

@haikalrios

Description

@haikalrios

Search before asking

  • I had searched in the issues and found no similar issues.

Question

Hello everyone, I'd like to share a question and hear your opinions on a specific behavior.

In a stateful application where we use a JWT access token in the authorization header (an approach that might seem odd for combining stateful with JWT), on the first request, the subject is assigned to the session, making it authenticated. Thus, subsequent requests are accepted until the session is invalidated. My question is: considering that the JWT token has its own validity period, would it make sense to revalidate the token with each request, or should we rely entirely on session management? Furthermore, within the context of Shiro, is there a specialized JWT filter and, in this filter, would a session be mandatory?

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions