The Token That Answers for Itself
Last timeNot Asking Again Every Time
A token can be a meaningless handle you look up, or a signed statement that answers the question by itself. The second is faster and cannot be taken back.
Handle or statement
The session identifier in the previous lesson was a handle. It is a long
random value that means nothing on its own; the meaning lives in your store,
and every request that carries it causes a lookup.
The alternative is to put the answer in the token. Instead of a random
string, the token is a short statement, something like this identity, these
permissions, issued at this time, valid until that time, with a
cryptographic seal attached. A receiver reads the statement, checks the seal
with a key it already has, and proceeds. It asks nobody anything.
a handle
8f3c1a9e4b7d2056c8e1f4a7b9d3e6c0a2f5b8d1
meaning: none, until the store is asked
check: one lookup, every request
a statement, decoded
{ sub: user-4417,
scope: read write,
iat: 1760000000,
exp: 1760000900,
iss: accounts.northwind,
aud: billing-service }
plus a seal over all of it
meaning: carried with it
check: verify the seal, read the datesThe appeal is immediate. No lookup means no shared database between
services, no round trip on the hot path, and a service in another team can
accept your tokens knowing only a public key. For a system of twenty
services handling a lot of traffic, that is a genuine architectural
simplification rather than a micro-optimisation.
| true of a handle | true of a signed stateme | usually wanted | the reason people choose | |
|---|---|---|---|---|
| needs a store on every r | 1 | 0 | 1 | 0 |
| readable by whoever hold | 0 | 1 | 0 | 1 |
| withdrawal takes effect | 1 | 0 | 1 | 0 |
| verifiable by a service | 0 | 1 | 0 | 1 |
| size grows with the perm | 1 | 0 | 0 | 1 |
| survives your database b | 0 | 1 | 1 | 0 |
| can be made longer-lived | 1 | 0 | 1 | 0 |
What the seal actually proves
Be exact about this, because a great deal of confused design follows from
being loose about it.
A valid signature proves two things. It proves origin: this statement was
produced by somebody holding the signing key, which should be only you. And
it proves integrity: not one character has changed since it was signed, so a
holder cannot promote themselves by editing the scope.
It proves nothing else. In particular it does not prove that the statement
is still true. The account may have been deleted, the permission revoked,
the password changed after a breach, the subscription cancelled. The seal
was correct at the moment of issue and remains correct forever, because it
is a statement about the past.
The lesson stops here
4 more paragraphs to go
You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.
The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.
See the planThe contentsThis is the reading half
Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.
The contents