How to destroy JWT Tokens on logout?

后端 未结 5 1659
[愿得一人]
[愿得一人] 2020-12-02 08:10

I am using jwt plugin and strategy in hapijs.

I am able to create jwt token while login user and authenticate other API using the same token through \'jwt\' strategy

5条回答
  •  谎友^
    谎友^ (楼主)
    2020-12-02 08:53

    You can add "issue time" to token and maintain "last logout time" for each user on the server. When you check token validity, also check "issue time" be after "last logout time".

提交回复
热议问题