logoalt Hacker News

littlecranky67yesterday at 8:43 PM1 replyview on HN

The story changes if you have a distributed database. replicating a smaller revocation list (that is append only) that will never be more than a couple of MB, is easier to do accross distributed nodes around the world than keeping a larger, session state db replicated. Heck, your revocation list can even be public (it contains only a list of substring of a few bytes of hashes).

Syncing sessins can be done, no question, I would just think JWT+revocation db is easier to implement, yet robust.


Replies

conradludgateyesterday at 10:03 PM

It can also be encoded as a bloom filter for very fast checks. Then you can defer to the replicated LSMTree that's stored replicated on your local node