Stateless tokens vs server-side sessions and token rotation.
01
01
Understand the problem
nodejssecurityjwtauth
02
02
Attempt it yourself
Sketch your approach before reading the solution — that's what interviews test.
Stuck? AI Nudge Available
Get a conceptual hint to guide your logic without spoiling the final implementation.
03
03
Study the solution
The solution is waiting
Give it an honest attempt first — then compare your thinking with the full walkthrough.
04
04
Read the code
Access + refresh token issue/rotate
import jwt from 'jsonwebtoken';
// short-lived access token (stateless)
const access = jwt.sign({ sub: user.id, roles: user.roles }, SECRET, { expiresIn: '10m' });
// long-lived refresh token: store a hash server-side so it's revocable + rotatable
const refresh = crypto.randomUUID();
await db.saveRefresh({ userId: user.id, hash: sha256(refresh) });
res.cookie('rt', refresh, { httpOnly: true, secure: true, sameSite: 'strict' });05
05
Join the discussion
Discussion (0)
Sign in to join the discussion.
No responses yet. Be the first to share what you think.