another way JWTs show up is no cookie at all; an api call with Authorization: Bearer eyJhbGc.. in the header. this is actually more common for JWTs in practice, especially for mobile apps and public apis, since cookies don't really work the same way outside a browser.
a set-cookie isn't the session side of this, it's just the delivery method. what actually decides session based vs JWT is the type of id sitting inside that cookie.
that cookie only proves you're logged in, it says nothing about how strong your login is once it's gone. picking the wrong one means either you can't kick out a compromised account fast enough, or you overbuilt for a problem you never had.
a random id like session_id=abc123 that the server looks up in a database, that's session based auth riding on a cookie. a full JWT sitting inside that same cookie instead, that's JWT based auth using the identical delivery mechanism. same envelope, different things it can carry.
bombolonis at the Piatto Cafe in Pune and I'm already thinking when I'm going back lol. didn't take pics but the vibe alone was worth it along with some good work done
a token isn't valid for 15 minutes, it's valid until a timestamp, and the server reading it decides whether that timestamp has passed. a token that expires at 3:00 only works if every server agrees what 3:00 is.
a token isn't valid for 15 minutes, it's valid until a timestamp, and the server reading it decides whether that timestamp has passed. a token that expires at 3:00 only works if every server agrees what 3:00 is.
that cookie only proves you're logged in, it says nothing about how strong your login is once it's gone. picking the wrong one means either you can't kick out a compromised account fast enough, or you overbuilt for a problem you never had.
the catch is that HTTP was never built to remember anyone. every request arrives as a stranger and never changes no matter. the thing keeping you logged in is a cookie the server handed your browser once and re-sent it on every request since.
first one's session based, the server keeps an actual record of your login so deleting that row logs you out right away. second is JWT based, the token carries your identity inside itself and the server just checks a signature, nothing to delete on its end.
picture two apps that both promise 'you'll stay logged in.' one kills your access instantly the moment something looks off. the other can't touch it until the token expires hours later, no matter what anyone notices in the meantime.