Don't store access/session tokens directly. Use tokens from a CSRNG and store the cryptographically secure hash of it. Hash on each request
-
-
I'm very interested too. Currently trying out macaroons, home-baked buscuits, JWT rolls and cookies and none are particularly tasty :)
-
It's exactly like the original tweet, ie. very non-fancy, so maybe a bit too bland for your tastes :p
- 2 more replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.