Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Json Web Token at Employment Hero
Search
Sponsored
·
Ship Features Fearlessly
Turn features on and off without deploys. Used by thousands of Ruby developers.
→
Luong Vo
September 11, 2018
Programming
44
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Json Web Token at Employment Hero
Luong Vo
September 11, 2018
More Decks by Luong Vo
See All by Luong Vo
Why our platform needs Redis Sentinel
luongvo
0
100
Performance Monitoring at Employment Hero
luongvo
0
160
Lalaland - A C2C ecommerce site - pitch deck
luongvo
0
450
Skeleton-based Human Action Recognition with Recurrent Neural Network
luongvo
0
260
Ruby Threads
luongvo
1
41
Caching in Ruby
luongvo
1
38
Monitoring system at Employment Hero
luongvo
0
58
Introduction to Docker and Docker Compose
luongvo
0
75
Database migration from Heroku to Amazon Web Services
luongvo
0
81
Other Decks in Programming
See All in Programming
Apache Hive: Toward a Cloud Native Lakehouse
okumin
0
180
Claude Code全社展開のためにやったことn選~プラグイン302個・コミッター271人を支えるために~
kenchan
4
1.3k
為什麼你並不需要ViewModel / No, you don't need a ViewModel
lovee
1
480
ビデオ通話が繋がる0.2秒で何が起きているのか
supurazako
2
170
「人を評価する AI」の設計と実装
ryoyanara
0
150
Terraform標準の組織で AWS CDKをどう使うか
mu7889yoon
1
480
Apache Hive: そしてCloud Native Lakehouseへ
okumin
1
200
freee が目指す データ マネジメント戦略 AI-Ready 時代を支える 攻めのガバナンスとは
freee
PRO
0
260
Claude CodeとAgentCore Gatewayを繋ぐ際の認証認可 / Authentication and authorization when connecting Claude Code with AgentCore Gateway
har1101
1
200
Claude Opus 4.6以後の受託開発エンジニアの変化(Claude Code開発ノウハウ大公開スペシャルbyクラスメソッド)
iidatakuma
1
970
2年かけて Deno に DOMMatrix を実装した話 / How I implemented DOMMatrix in Deno over two years
petamoriken
0
200
Built Our Own Background Agent at LayerX
layerx
PRO
9
4.9k
Featured
See All Featured
Imperfection Machines: The Place of Print at Facebook
scottboms
270
14k
The #1 spot is gone: here's how to win anyway
tamaranovitovic
3
1.1k
Neural Spatial Audio Processing for Sound Field Analysis and Control
skoyamalab
0
400
Impact Scores and Hybrid Strategies: The future of link building
tamaranovitovic
0
360
Color Theory Basics | Prateek | Gurzu
gurzu
0
410
16th Malabo Montpellier Forum Presentation
akademiya2063
PRO
0
320
Self-Hosted WebAssembly Runtime for Runtime-Neutral Checkpoint/Restore in Edge–Cloud Continuum
chikuwait
0
680
From π to Pie charts
rasagy
0
250
The Cost Of JavaScript in 2023
addyosmani
55
10k
Exploring anti-patterns in Rails
aemeredith
3
450
How to build an LLM SEO readiness audit: a practical framework
nmsamuel
1
830
Measuring & Analyzing Core Web Vitals
bluesmoon
9
950
Transcript
JSON Web Tokens Luong Vo
None
None
None
None
None
None
JSON Web Token
What is JSON Web Tokens
JSON Object To transfer data between two parties digitally signed
Digitally signed JSON Data Signature JSON Web Token
Signature signing algorithm
RSA256
HSA256
Comparison RSA256 HSA256
None
None
JSON API Authentication
Main app Username + password Session token Auth Service Generate
session token Save session token to database But why?
Main app Session token JWT Token Auth Service Generate JWT
Query session token to check But why?
Main app Get/…. + JWT Token { “data”: …. }
Auth Service Validate JWT But why?
Main app Get/…. + JWT Token { “data”: …. }
Auth Service Validate JWT Microservice GRPC call But why?
Microservice API Call !? Oh….
Main app Get/…. + JWT Token { “data”: …. }
Auth Service Validate JW T Microservice Oh….
External system Main app Microservice
None
Microservice API Call Should we? Auth Service authenticate
Microservice API Call Better! LOAD BALANCER Auth Service authenticate API
Gateway
Main app Get/…. + JWT Token { “data”: …. }
Auth Service Microservice LOAD BALANCER
None
None
None
https://github.com/Thinkei/eh-kong/blob/master/auth/handler.lua#L49
None
Why not just use JWT
Size User ID in JWT User id in session token
• Require CPU to compute cryptographic signatures • No utilisation
of being stateless • Redundant-signing • Can be read on the client side • Must be explicitly encrypted if we wanted to • Hard revocation
That’s it. Thank you for your attention!