Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
jsconf.uy - Death to Cookies Long Live Tokens
Search
Sponsored
·
Ship Features Fearlessly
Turn features on and off without deploys. Used by thousands of Ruby developers.
→
Matias Woloski
March 15, 2014
Technology
44
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
jsconf.uy - Death to Cookies Long Live Tokens
Matias Woloski
March 15, 2014
More Decks by Matias Woloski
See All by Matias Woloski
Death to Cookies, Long Live JSON Web Tokens
woloski
2
270
Death to Cookies Long Live Tokens - Gluecon 2014
woloski
0
180
Death to Cookies, Long Live Tokens
woloski
5
690
Other Decks in Technology
See All in Technology
FORENSIA: ローカルLLMフォレンジックハーネス
sumeshi
2
440
医療の現場を変革に挑戦した半年間の軌跡 - PythonとAIで現場を変える / From Code to Care
soudai
PRO
0
530
Flutter × BLE Centralを自前Pluginで実装する設計パターン - MethodChannel / EventChannelで作る双方向ブリッジの実践 / Building Custom Flutter BLE Central Plugins: Bidirectional Bridging with Method & Event Channels
bitkey
PRO
0
220
Kiro Crew入門 - 常駐エージェントの仕組みと使いどころ / Intro to Kiro Crew
k_adachi_01
1
750
小粒でもパワフルなJS Runtime Antjsについて
comamoca
0
120
カーネルまで探検して理解するふたつの自動計装
sumiyae
0
150
トークンマネジメントでAIにとって働きやすい環境を実現する
hikaruegashira
0
140
AI時代のアウトプット――変わったこと、変わらないこと / Devsumi 2026 Kansai #devsumi
jnchito
0
500
AIに狂うスタートアップが、あえて「人との協働」に全振りした新卒エンジニア研修 / New Graduate Engineer Training at a Startup Accelerating AI Adoption
ohnoeight
0
180
RapidCopy2 Matrix I/Oエンジンによるファイルコピーソフトウェアの設計と実装
kengosawa2
1
270
老害フォレンジッカーはAI羊の夢を見るか?
tadmaddad
0
360
AIに持続⼒を与える 判断の⻑期記憶設計
eiei114
1
630
Featured
See All Featured
Building Experiences: Design Systems, User Experience, and Full Site Editing
marktimemedia
0
580
Future Trends and Review - Lecture 12 - Web Technologies (1019888BNR)
signer
PRO
0
3.7k
Practical Orchestrator
shlominoach
191
12k
Conquering PDFs: document understanding beyond plain text
inesmontani
PRO
4
3k
Building AI with AI
inesmontani
PRO
1
1.1k
ReactJS: Keep Simple. Everything can be a component!
pedronauck
666
130k
Kristin Tynski - Automating Marketing Tasks With AI
techseoconnect
PRO
0
480
So, you think you're a good person
axbom
PRO
2
2.1k
Unsuck your backbone
ammeep
672
58k
The Director’s Chair: Orchestrating AI for Truly Effective Learning
tmiket
1
280
RailsConf 2023
tenderlove
30
1.5k
Sharpening the Axe: The Primacy of Toolmaking
bcantrill
46
3k
Transcript
Death to Cookies Long Live Tokens @woloski @jfroma
None
None
Client Database auth persistent connection 1990’s Client Server Life was
easy
Workstation Browser Database auth 2000’s Intranet Web Server Active Directory
kerberos token Life inside corp
Workstation Browser Database Internet Web Server auth C C E-commerce
Browser Database Today’s applications Web Server (Scala) API (Ruby) API
(Node) Phones Tablets Realtime (Sockets) API (Facebook) C M A A A AT
+80K Views
None
Cookie-based auth is a sub- optimal solution for today’s systems
Set-Cookie + CORS = doesn’t play well 1
Cookies are coupled to the web framework ! If you
try to reuse a cookie issued by Java in Node, not easy 2
APIs don’t use cookies, native apps either 3
Cookies lead to CSRF attacks <iframe style="display:none" name="hidden"></iframe> <form
name="csrf" action="http://example.org/account/edit" method="post" target="hidden"> <input type="hidden" name="email" value="
[email protected]
" /> <script>document.csrf.submit();</script> 4
http://tools.ietf.org/html/draft-ietf-oauth-json-web-token
How it works?
Not everything is pink color
art: http://abeon-hosting.com/security-blog/xss-attack-in-action-cookie-stealer/ Tokens XSS
Sanitize and encode everything ! Google Caja https://developers.google.com/caja/
Try token-based authentication in your next project
TOOOOOOOOKEEEENS
Thanks! @woloski @jfroma blog.auth0.com jwt.io
Appendix
None
None
JWT JSON Web Tokens eyJ0eXAiOiJKV1QiLC JhbGciOiJIUzI1NiJ9 .eyJ1c2VyX2lkIjoiM TIzNDUiLCJlbWFpbCI 6ImZvb0BiYXIuY29tI
iwiZXhwIjoxMzkyMzI zMzQwLCJpYXQiOjEzO TIzMTYxNDB9 .KQma3tquGF_zKbLdX HV4zNJAupdHJdIk6L2 g6R8kcAY ! ! { "typ":"JWT", "alg":"HS256" } { "user_id": "12345", "email" : "
[email protected]
", "exp": 1392323340, "iat": 1392316140 } HMACSHA256( base64UrlEncode(header) + "." + base64UrlEncode(payload), "secret") ! header payload signature encoded decoded
Token expires, deal with refresh
Confidential info, encrypt it
Social auth
Tokens can get big Don’t over engineer Don’t do fine
grained permissions Define scopes
How to deal with protected images? https://github.com/hueniverse/hawk#single-uri-authorization Create signed requests
(single URI authorization)