Rank 4: Virtual Machine
What's your go-to path for JWT tokens?
I currently store the a_session_projectid as a cookie, but secure and without HTTPOnly. Normally you should use HTTPOnly but I don't want to create a new JWT token for every request. Or should I?
The token is as you said 15 minutes valid. Do I store it for 15 minutes and create a new one after that? Do I check for the JWT validation the entire time to create a new one? 😄
or do I just create a JWT token every time I do a request? (Which is a lot)