7 ms·
That was a bit edgey, but I have seen far too many devs recreate OIDC using JWT. Writing their own token parsing and validation. Doing their own token expiratio
by deviledeggs 5y ago
That was a bit edgey, but I have seen far too many devs recreate OIDC using JWT. Writing their own token parsing and validation. Doing their own token expiration handling.
These days, just use OIDC. It takes care of everything for you. Most of the time, you just point your OIDC library at your auth server URL and it handles everything.