ãã¯ãããããã¾ããritouã§ãã ãã®è©±ã«ä¹ã£ãã£ã¦ããã¾ãã 3è¡ã§ ãã°ã¢ã¦ãæã«JWTãç¡å¹åã§ããªãå®è£ ã¯ä»å¾èå¼±æ§è¨ºæã§ãOWASP Top 10 2021éåãã¨ææãããããã«ãªããã(ä»ãåå¥ã«ããã¦ããããããªããã©) JWTã¯åç´ãªãã©ã¼ããããªã®ã§ãã¹ãã¼ãã¬ã¹ãªã»ãã·ã§ã³ç®¡çã«ããã¦ãã°ã¢ã¦ãããã¨ãã«æååèªä½ãç¡å¹åã§ããªã件ã¯ç¬èªã¨ã³ã³ã¼ãæ¹å¼(ä¸è¬çã«ãã¬ã¼ã ã¯ã¼ã¯ã®Cookieã¹ãã¢ã¨å¼ã°ãã¦ãããã®)ã§ãèµ·ããå¾ã ãã»ãã·ã§ã³ID vs JWTã§å å ã 以å¤ã«ã ãã»ãã·ã§ã³IDãJWTã«å å ããããå¾ããæ¢åã®æ©è½ãæ®ãã¤ã¤ãJWTã§æ¦è£ ãããé¸æè¢ãèãã¦ã¿ã¦ã¯ã©ããã ã¹ãã¼ãã¬ã¹ãªã»ãã·ã§ã³ç®¡çã§ãã°ã¢ã¦ãã®éã«æååèªä½ãç¡å¹åã§ããªãåé¡ ããã¯åããè¨ããã¦ãã¾ãããé§ãåºãä½ã¨ãå¢ã®Qiitaè¨äºã«æ¸ããããããã«ã¯ä¸è¬çã§ãã 2
{{#tags}}- {{label}}
{{/tags}}