Hacker News new | past | comments | ask | show | jobs | submit login

Which headaches would that be?



That you have to keep a white/blacklist if you want to revoke a token.


Blacklisting is only half the problem. Trying to emulate the same UX of regular sessions (staying logged-in etc) is the bigger pain point.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: