Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
jsconf.uy - Death to Cookies Long Live Tokens
Search
Matias Woloski
March 15, 2014
Technology
44
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
jsconf.uy - Death to Cookies Long Live Tokens
Matias Woloski
March 15, 2014
More Decks by Matias Woloski
See All by Matias Woloski
Death to Cookies, Long Live JSON Web Tokens
woloski
2
270
Death to Cookies Long Live Tokens - Gluecon 2014
woloski
0
180
Death to Cookies, Long Live Tokens
woloski
5
690
Other Decks in Technology
See All in Technology
synctest時代のhttptest Go 1.27で変わるHTTPサーバテストの裏側 / go conference2026 synctest and httptest
budougumi0617
1
2.6k
DEFCON_CHV_CTF_Write-up.pdf
bata_24
0
140
Adaptive Warehouse を今すぐ導入すべき理由と迷ったときの判断基準
__allllllllez__
0
170
GoにおけるFFIのこれまでとこれから
goccy
5
2.4k
2026_devsumi_ozono.pdf
o3
2
370
生成AIのテナント制御とシャドーMCP対策 | AIを"止めずに"、情報を守る
yukun
0
150
Snowflakeで実現する全社横断の顧客の声(VOC)分析・活用基盤@Snowflake World Tour Tokyo 2026
yuto16
0
170
TinyGo 開発サイクルを高速化する:Go で作るエミュレータ入門
zozotech
PRO
1
610
アプリをもっと"iOSアプリっぽく"する小さな工夫 / Small Touches That Make Your App Feel More Like an iOS App
matsuji
1
520
「図書館」という名前のままでいいのか -Code4Lib JAPANカンファレンス2026 アンカンファレンス報告- / Code4Lib JAPAN Conference 2026: Unconference Report
ykiyota
0
160
なぜSRE・セキュリティは評価されないのか?守りの組織を事業成長エンジンに変えた実践
cscengineer
PRO
3
2.5k
Slack上でインフラをトラブルシュートする! Agentic Platform Engineeringの第一歩
teru0x1
2
760
Featured
See All Featured
Cheating the UX When There Is Nothing More to Optimize - PixelPioneers
stephaniewalter
287
14k
Producing Creativity
orderedlist
PRO
348
41k
The Power of CSS Pseudo Elements
geoffreycrofte
82
6.6k
Measuring Dark Social's Impact On Conversion and Attribution
stephenakadiri
2
270
VelocityConf: Rendering Performance Case Studies
addyosmani
331
25k
Ten Tips & Tricks for a 🌱 transition
stuffmc
0
210
The SEO identity crisis: Don't let AI make you average
varn
0
550
Ethics towards AI in product and experience design
skipperchong
2
370
Why Mistakes Are the Best Teachers: Turning Failure into a Pathway for Growth
auna
0
270
The Director’s Chair: Orchestrating AI for Truly Effective Learning
tmiket
1
290
Heart Work Chapter 1 - Part 1
lfama
PRO
9
36k
Building Applications with DynamoDB
mza
96
7.2k
Transcript
Death to Cookies Long Live Tokens @woloski @jfroma
None
None
Client Database auth persistent connection 1990’s Client Server Life was
easy
Workstation Browser Database auth 2000’s Intranet Web Server Active Directory
kerberos token Life inside corp
Workstation Browser Database Internet Web Server auth C C E-commerce
Browser Database Today’s applications Web Server (Scala) API (Ruby) API
(Node) Phones Tablets Realtime (Sockets) API (Facebook) C M A A A AT
+80K Views
None
Cookie-based auth is a sub- optimal solution for today’s systems
Set-Cookie + CORS = doesn’t play well 1
Cookies are coupled to the web framework ! If you
try to reuse a cookie issued by Java in Node, not easy 2
APIs don’t use cookies, native apps either 3
Cookies lead to CSRF attacks <iframe style="display:none" name="hidden"></iframe> <form
name="csrf" action="http://example.org/account/edit" method="post" target="hidden"> <input type="hidden" name="email" value="
[email protected]
" /> <script>document.csrf.submit();</script> 4
http://tools.ietf.org/html/draft-ietf-oauth-json-web-token
How it works?
Not everything is pink color
art: http://abeon-hosting.com/security-blog/xss-attack-in-action-cookie-stealer/ Tokens XSS
Sanitize and encode everything ! Google Caja https://developers.google.com/caja/
Try token-based authentication in your next project
TOOOOOOOOKEEEENS
Thanks! @woloski @jfroma blog.auth0.com jwt.io
Appendix
None
None
JWT JSON Web Tokens eyJ0eXAiOiJKV1QiLC JhbGciOiJIUzI1NiJ9 .eyJ1c2VyX2lkIjoiM TIzNDUiLCJlbWFpbCI 6ImZvb0BiYXIuY29tI
iwiZXhwIjoxMzkyMzI zMzQwLCJpYXQiOjEzO TIzMTYxNDB9 .KQma3tquGF_zKbLdX HV4zNJAupdHJdIk6L2 g6R8kcAY ! ! { "typ":"JWT", "alg":"HS256" } { "user_id": "12345", "email" : "
[email protected]
", "exp": 1392323340, "iat": 1392316140 } HMACSHA256( base64UrlEncode(header) + "." + base64UrlEncode(payload), "secret") ! header payload signature encoded decoded
Token expires, deal with refresh
Confidential info, encrypt it
Social auth
Tokens can get big Don’t over engineer Don’t do fine
grained permissions Define scopes
How to deal with protected images? https://github.com/hueniverse/hawk#single-uri-authorization Create signed requests
(single URI authorization)