The jwt is invalidated once you logout.
Invalidated how?
You can also change/reset your password to invalidate all login tokens for your account.
OK. I was afraid this would not be the case. Thanks for confirming.
The jwt is invalidated once you logout.
Invalidated how?
You can also change/reset your password to invalidate all login tokens for your account.
OK. I was afraid this would not be the case. Thanks for confirming.
One thing to be aware of is that there is currently, AFAIK, no now (since 0.19.3) a way to “disable” a JWT.
Before that, once you had created it, if you leaked it, your account was, as far as I can tell, definitely compromised.
Now, it is possible to logout, to mark the JWT as “invalid”.
I will add, as a disclaimer, that I have not checked if that as Nutomic highlighted below, there are conditions (password change, etc) under which any or all JWT (user, instance, etc) become invalid. So do audit the code if this is something that concerns you. As far as I am concerned, I treat the JWTs as extra-sensitive information, and store them only on machines I own.
Edit: correct information in the light of Nutomic’s comments.
As people have answered, it already exists, but not every client has support.
Edit: how tf did you get downvoted in 8h on a dead post??? 😧
Hold on, is that a grant or a donation? (The difference is that a donation is definitive, while there are conditions, such as failing to fulfil an obligation, under which a grant has to be repaid)
“Belgium nationality”. 💯👍
expired
I can’t wait for the first of April Lemmy RFC featuring actual lemmings… 😛
expired
expired
What’s the count now anyway?
OK there now is a
LoginToken
class. This was not the case last time I checked. Good. Thanks for your answers.