Don't store access/session tokens directly. Use tokens from a CSRNG and store the cryptographically secure hash of it. Hash on each request
-
-
Replying to @emilbayes
Ohh, speaking of: did you make any progress on your idea for session tokens? :D
1 reply 0 retweets 0 likes -
Replying to @yoshuawuyts
Hehe, I have a module on my laptop now, just need some review on API
1 reply 0 retweets 1 like -
Replying to @emilbayes
If you want, I'd be happy to review anything you got!
1 reply 0 retweets 0 likes -
Replying to @yoshuawuyts @emilbayes
I'm very interested too. Currently trying out macaroons, home-baked buscuits, JWT rolls and cookies and none are particularly tasty :)
1 reply 0 retweets 1 like -
Replying to @NokomeBentley @yoshuawuyts
It's exactly like the original tweet, ie. very non-fancy, so maybe a bit too bland for your tastes :p
1 reply 0 retweets 1 like
We all want the triple chocolate pistachio laced caramel version of your CRYPTO SESSIONS MODULE
-
-
Replying to @yoshuawuyts @NokomeBentley
This is going to be that low-sugar, non-fatty token diet that will save you from your blockchain induced lifestyle diseases
0 replies 0 retweets 4 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.