Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is that true? The token may have the time encoded in it. When the token is presented to the server it responds with a 401. The client can then use the WWW-Authenticate response to know what to do next.

None of this requires state on the server.



But it requires a state on the client still.

I need to store a state somewhere at least. That’s not really stateless.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: