
Rotate a JWT signing key the naive way, swap it out and redeploy, and every token issued under the old key stops verifying the instant you deploy. Every logged-in user gets kicked out at once. This is one of those problems that's obvious…
View original source — Hacker Noon ↗


