ãã£ãã æ¨å¹´(2021å¹´9æãã)ã«å¾³ä¸¸ããã®ãã®ãã¤ã¼ããè¦ã¦ãã2022å¹´ã«ã¯JWTãç¨ããã»ãã·ã§ã³ç®¡çã«ä»£è¡¨ããããã¹ãã¼ãã¬ã¹ãªã»ãã·ã§ã³ç®¡çã¯ä¸ã®ä¸ã«åãå ¥ããããªããªã£ã¦ããã®ã ãããï¼ãã¨æã£ã¦ãã¾ããã OWASP Top 10 2021 A1ã«ãJWT tokens should be invalidated on the server after logout.ãï¼ç§è¨³:JWTãã¼ã¯ã³ã¯ãã°ã¢ã¦ãå¾ã«ãµã¼ãã¼ä¸ã§ç¡å¹åãã¹ãã§ãï¼ã¨æ¸ãã¦ãããã©ãã©ããã£ã¦ç¡å¹åãããã ? ãã©ãã¯ãªã¹ãã«å ¥ãã?https://t.co/bcdldF82Bwâ 徳丸 浩 (@ockeghem) 2021å¹´9æ10æ¥ JWT大好ããªçãããããã¯ã¦ã©ããããªãã¨ã ãã§ãããããããã®ã¾ã¾éã£ããããã°ã¢ã¦ãæ©è½ã§JWTã®å³æç¡å¹åããã¦ããªããµã¤ãã¯èå¼±æ§è¨ºæã§ãOWASP Top
{{#tags}}- {{label}}
{{/tags}}