Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The advantage -- and it's often a big one -- is that you don't have to have a corresponding server component to translate session id to session state. The state is all in the client.

Edit: wouldn't have written this if I'd seen FooBarWidget's more detailed remarks first.



"Never trust the client"


The session information is cryptographically signed, so you don't have to trust it! These stateless server frameworks are just using the client as a state cache.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: