2
Support revoking access tokens by JWT blacklist
Source: supabase/supabase#33791 · opened by @typed-sigterm
Maybe we can have a list of revoked access tokens, when using access tokens in the list, report as expiring. Then revoking sessions is possible.
It's not so security that giving another 1 hour to hackers after the user found their account has been stolen.
It's not so security that giving another 1 hour to hackers after the user found their account has been stolen.
No pledges yet. Be the first to back this.
Comments
Similar requests
Changing JWTs to RS256 to verify JWT inside getSession() anywhere
4 votes · 0 comments
PAT security vulnerability for MCP - prod access
2 votes · 0 comments
Email Verification API support with SD-JWT for native email verification
2 votes · 0 comments
Phone Blacklist
3 votes · 0 comments
Support API key generation
18 votes · 0 comments
No comments yet.