Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
jsconf.uy - Death to Cookies Long Live Tokens
Search
Sponsored
·
SiteGround - Reliable hosting with speed, security, and support you can count on.
→
Matias Woloski
March 15, 2014
Technology
44
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
jsconf.uy - Death to Cookies Long Live Tokens
Matias Woloski
March 15, 2014
More Decks by Matias Woloski
See All by Matias Woloski
Death to Cookies, Long Live JSON Web Tokens
woloski
2
270
Death to Cookies Long Live Tokens - Gluecon 2014
woloski
0
180
Death to Cookies, Long Live Tokens
woloski
5
690
Other Decks in Technology
See All in Technology
DMM.com 購入改善推進チーム におけるCodeRabbitを用いた レビューフロー改善の一例
ysknsid25
2
660
第67回コンピュータビジョン勉強会CVPR2026読会前編
tsukamotokenji
0
140
凡エンジニアがこの先生きのこるためには。〜TypeScript完全に理解したい〜
alchemy1115
2
310
kintone の AI コワーカーを、 Anthropic にエージェントを"ホストさせて"作った話 #devkinmeetup
sugimomoto
0
110
誤解だらけの開発生産性 / Myths and Misconceptions about Developer Productivity
i35_267
2
780
CDKで書くECSのベストプラクティス、 改めて考え直す2026 #cdkconf2026
makies
3
760
AIと共生する開発者プラットフォーム:バクラクのモノレポ×マイクロサービス基盤
sakajunquality
2
3.7k
AIレビューはどこまで任せられるのか?自動化と人が背負うレビューの境界
sansantech
PRO
3
1.1k
AmplifyHostingConstructからSSRフレームワークのためのホスティング設計を考察する/amplify-hosting-construct
fossamagna
1
210
“それは自分の仕事じゃない"を越えて行け
yuukiyo
1
470
ソニー銀行におけるビジネスアジリティ向上のためのクラウドシフト戦略
srenext
0
710
Alphaモジュール使っていいのかい!?いけないのかい!?どっちなんだいっ!?
watany
1
260
Featured
See All Featured
Noah Learner - AI + Me: how we built a GSC Bulk Export data pipeline
techseoconnect
PRO
0
220
Designing for Performance
lara
611
70k
Raft: Consensus for Rubyists
vanstee
141
7.6k
The #1 spot is gone: here's how to win anyway
tamaranovitovic
3
1.1k
Unlocking the hidden potential of vector embeddings in international SEO
frankvandijk
0
870
Intergalactic Javascript Robots from Outer Space
tanoku
273
27k
AI Search: Where Are We & What Can We Do About It?
aleyda
0
7.7k
30 Presentation Tips
portentint
PRO
1
350
The Web Performance Landscape in 2024 [PerfNow 2024]
tammyeverts
12
1.2k
Facilitating Awesome Meetings
lara
57
7k
Introduction to Domain-Driven Design and Collaborative software design
baasie
1
900
Learning to Love Humans: Emotional Interface Design
aarron
275
41k
Transcript
Death to Cookies Long Live Tokens @woloski @jfroma
None
None
Client Database auth persistent connection 1990’s Client Server Life was
easy
Workstation Browser Database auth 2000’s Intranet Web Server Active Directory
kerberos token Life inside corp
Workstation Browser Database Internet Web Server auth C C E-commerce
Browser Database Today’s applications Web Server (Scala) API (Ruby) API
(Node) Phones Tablets Realtime (Sockets) API (Facebook) C M A A A AT
+80K Views
None
Cookie-based auth is a sub- optimal solution for today’s systems
Set-Cookie + CORS = doesn’t play well 1
Cookies are coupled to the web framework ! If you
try to reuse a cookie issued by Java in Node, not easy 2
APIs don’t use cookies, native apps either 3
Cookies lead to CSRF attacks <iframe style="display:none" name="hidden"></iframe> <form
name="csrf" action="http://example.org/account/edit" method="post" target="hidden"> <input type="hidden" name="email" value="
[email protected]
" /> <script>document.csrf.submit();</script> 4
http://tools.ietf.org/html/draft-ietf-oauth-json-web-token
How it works?
Not everything is pink color
art: http://abeon-hosting.com/security-blog/xss-attack-in-action-cookie-stealer/ Tokens XSS
Sanitize and encode everything ! Google Caja https://developers.google.com/caja/
Try token-based authentication in your next project
TOOOOOOOOKEEEENS
Thanks! @woloski @jfroma blog.auth0.com jwt.io
Appendix
None
None
JWT JSON Web Tokens eyJ0eXAiOiJKV1QiLC JhbGciOiJIUzI1NiJ9 .eyJ1c2VyX2lkIjoiM TIzNDUiLCJlbWFpbCI 6ImZvb0BiYXIuY29tI
iwiZXhwIjoxMzkyMzI zMzQwLCJpYXQiOjEzO TIzMTYxNDB9 .KQma3tquGF_zKbLdX HV4zNJAupdHJdIk6L2 g6R8kcAY ! ! { "typ":"JWT", "alg":"HS256" } { "user_id": "12345", "email" : "
[email protected]
", "exp": 1392323340, "iat": 1392316140 } HMACSHA256( base64UrlEncode(header) + "." + base64UrlEncode(payload), "secret") ! header payload signature encoded decoded
Token expires, deal with refresh
Confidential info, encrypt it
Social auth
Tokens can get big Don’t over engineer Don’t do fine
grained permissions Define scopes
How to deal with protected images? https://github.com/hueniverse/hawk#single-uri-authorization Create signed requests
(single URI authorization)