JWT's pros and cons

excellent

1: Stateless - Stateless
2: Portable - a Token may be simultaneously receiving a plurality of different languages rear / internet certification
3: cookies does not depend on (although the JWT storage or recommend the use HttpOnly + Secure stored, but after some people just do not like Cookie)
4: performance issues (perfect client uses JWT can reduce the number of communications between servers, such as gender-loving non-sensitive information, certifications and once JWT can LocalStorage store)
5: Decoupled / Decentralized - JWT can be generated at any place, at any place can be certified

inferior

1. Let not a single failure of the JWT token (typically token solution is stored in the server jwt, but this way there is put into a state stateless)

2. When a user updates their personal information, information JWT token before issuing will become obsolete in

Guess you like

Origin www.cnblogs.com/ephemeral/p/11946730.html