mediumBackend

What is the difference between JWT and session-based authentication, and where do refresh tokens fit?

384 views
01

Understand the problem

Stateless tokens vs server-side sessions and token rotation.

nodejssecurityjwtauth
02

Attempt it yourself

Sketch your approach before reading the solution — that's what interviews test.

Stuck? AI Nudge Available

Get a conceptual hint to guide your logic without spoiling the final implementation.

03

Study the solution

The solution is waiting

Give it an honest attempt first — then compare your thinking with the full walkthrough.

04

Read the code

Access + refresh token issue/rotate
import jwt from 'jsonwebtoken';

// short-lived access token (stateless)
const access = jwt.sign({ sub: user.id, roles: user.roles }, SECRET, { expiresIn: '10m' });

// long-lived refresh token: store a hash server-side so it's revocable + rotatable
const refresh = crypto.randomUUID();
await db.saveRefresh({ userId: user.id, hash: sha256(refresh) });

res.cookie('rt', refresh, { httpOnly: true, secure: true, sameSite: 'strict' });
05

Join the discussion

Discussion (0)

Sign in to join the discussion.

No responses yet. Be the first to share what you think.