Skip to content
This repository was archived by the owner on May 24, 2023. It is now read-only.
This repository was archived by the owner on May 24, 2023. It is now read-only.

We should not silently put JWT to ctx.Locals() #58

@shytikov

Description

@shytikov

Currently on successful validation token is always saved to ctx.Locals(), but I'm not sure it's necessary, as if we can always get this information from the ctx anyway, either headers, or cookies or URL params. What might be valuable is to have claims saved instead.

And in any case, we should not decide, but rather give a developer an option on how to treat this situation – the best would be to update the signature of SuccessHandler and pass a JWT there. And in case if a developer need it – he / she could save information that they need where they want. While today it's even impossible to switch off this behavior.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions