Spring Security 6 & JWT Authentication · Leçon

Listes noires et listes blanches de JWT

Approfondissez les techniques avancées de révocation des jetons, notamment la gestion de listes noires ou blanches de jetons.

Leçon 2 sur 411 étapes

Listes noires et listes blanches de JWT est une leçon Spring Security 6 & JWT Authentication gratuite sur CoddyKit. Ceci est la leçon 2 sur 4. Tu peux lire la leçon complète ci-dessous gratuitement — puis la pratiquer en direct dans le navigateur avec un éditeur de code intégré et un tuteur IA 24/7. Elle fait partie du parcours d'apprentissage Spring Security 6 & JWT Authentication, et ta progression se synchronise sur le web et l'application CoddyKit. Le cours Spring Security 6 & JWT Authentication comprend 4 leçons au total.

Certaines parties de cette leçon n'ont pas encore été traduites et s'affichent en anglais.

Why Revoke JWTs?

JSON Web Tokens (JWTs) are powerful for authentication, but sometimes you need to invalidate them before their natural expiry. This process is called token revocation.

  • Compromised Token: If a token is stolen.
  • User Logout: To immediately end a user's session.
  • Password Change: To invalidate all old tokens.
  • Role Changes: To force re-authentication with new permissions.

The Stateless Challenge

JWTs are inherently stateless. Once issued, they contain all necessary information for validation and don't require the server to store session data.

This statelessness is a strength, but it makes direct server-side revocation tricky. The server typically doesn't hold a list of active tokens to simply 'turn off'.

Blacklisting Explained

Blacklisting is a common strategy to revoke JWTs. When a token needs to be invalidated, its unique identifier (often the JTI claim) is added to a 'blacklist' — a list of forbidden tokens.

  • Any token whose JTI is on this list is rejected, even if it's cryptographically valid and not expired.
  • This allows you to 'undo' a token's validity.

Implementing a Blacklist

The blacklist needs to be stored in a highly available, fast-access data store. Speed is crucial because every incoming request might need to check this list.

  • Redis: An excellent choice due to its in-memory nature and support for time-to-live (TTL) on entries, which can match token expiry.
  • Database: A simple table can work, but might be slower for high-volume checks.
  • Each entry typically stores the JWT's JTI and its original expiry time.

Simple Blacklist Service

Here's a basic interface for a service that manages a token blacklist. In a real application, this would interact with a database or a caching system like Redis.

public interface TokenBlacklistService {
  void blacklistToken(String jti, long expirySeconds);
  boolean isBlacklisted(String jti);
}

JWT Filter with Blacklist Check

When a request arrives, a security filter would first validate the JWT's signature and expiry. Then, it would check if the token's JTI is present on the blacklist before granting access.

Try running this example:

import java.util.HashSet;
import java.util.Set;

// A simplified in-memory blacklist for demonstration
class MockTokenBlacklistService {
    private Set<String> blacklistedJtis = new HashSet<>();

    public void blacklistToken(String jti, long expirySeconds) {
        System.out.println("Action: Blacklisting JTI " + jti);
        blacklistedJtis.add(jti);
        // In a real app, 'expirySeconds' would set a TTL on the blacklist entry
    }

    public boolean isBlacklisted(String jti) {
        boolean result = blacklistedJtis.contains(jti);
        System.out.println("Check: Is JTI " + jti + " blacklisted? " + result);
        return result;
    }
}

public class Main {
    public static void main(String[] args) {
        MockTokenBlacklistService blacklist = new MockTokenBlacklistService();

        String userTokenJti = "user-abc-123";
        String adminTokenJti = "admin-def-456";

        // Simulate an admin token being revoked after a security event
        blacklist.blacklistToken(adminTokenJti, 3600); // Token expires in 1 hour

        // Check access for different tokens
        System.out.println("\n--- Access Checks ---");
        System.out.println("User token access: " + (blacklist.isBlacklisted(userTokenJti) ? "DENIED" : "GRANTED"));
        System.out.println("Admin token access: " + (blacklist.isBlacklisted(adminTokenJti) ? "DENIED" : "GRANTED"));
    }
}

Whitelisting Explained

Whitelisting is an alternative revocation strategy. Instead of listing forbidden tokens, you maintain a list of active, allowed tokens.

  • When a token is issued, its JTI is added to a 'whitelist'.
  • For every request, the token's JTI must be found on this whitelist to be considered valid.
  • If a token's JTI is not on the whitelist, it's rejected.

Implementing a Whitelist

Similar to blacklisting, a whitelist requires a fast, persistent store (e.g., Redis). The key difference is what you store and how you manage it:

  • Each entry typically stores the JWT's JTI, often associated with a user ID.
  • When a user logs out or changes their password, all active JTIs associated with that user can be efficiently removed from the whitelist.

Blacklist vs. Whitelist Comparison

Both strategies achieve revocation but have different implications:

  • Blacklist: Ideal for rare, specific revocations (e.g., single token compromise). Requires less storage if revocations are infrequent.
  • Whitelist: Better for frequent revocations (e.g., user logout invalidates all tokens). Can simplify session management but requires more storage for all active tokens.
  • The choice depends on your application's specific needs and the frequency of revocations.

Revocation Scenario

Consider an application where users frequently log out, and you need to ensure all their issued tokens are immediately invalidated upon logout.

Recap: Revocation Strategies

In this lesson, we've explored advanced strategies for revoking JWTs, which is crucial for robust security:

  • Blacklisting: Marking specific tokens as invalid by adding their JTI to a forbidden list.
  • Whitelisting: Only allowing tokens that are explicitly listed as active, often tied to a user session.
  • The best approach depends on your application's requirements, especially the frequency and nature of token invalidation.

Next, we'll analyze the performance implications of these techniques.

Gratuit pour commencer

Apprends Java avec un tuteur IA — gratuit

Écris et exécute du vrai code dans ton navigateur, obtiens de l'aide instantanée d'un tuteur IA disponible 24h/24, et reprends là où tu t'es arrêté sur le web ou dans l'app.

Cours
12
Leçons
48

Questions Fréquemment Posées

La leçon « Listes noires et listes blanches de JWT » est-elle gratuite ?

Oui — le texte complet de « Listes noires et listes blanches de JWT » est gratuit à lire ici sur le web. Pour la pratiquer de manière interactive (un éditeur de code intégré et un tuteur IA 24/7) et déverrouiller le reste du cours Spring Security 6 & JWT Authentication, passe à CoddyKit PRO. Le cours Spring Security 6 & JWT Authentication comprend 4 leçons au total.

Qu'est-ce que j'apprendrai dans « Listes noires et listes blanches de JWT » ?

Approfondissez les techniques avancées de révocation des jetons, notamment la gestion de listes noires ou blanches de jetons. Tu pratiques Spring Security 6 & JWT Authentication avec du code pratique que tu exécutes directement dans le navigateur, et un tuteur IA 24/7 répond à tes questions au fur et à mesure que tu avances dans la leçon.

Dois-je avoir de l'expérience pour commencer Spring Security 6 & JWT Authentication ?

Aucune expérience préalable n'est requise. Spring Security 6 & JWT Authentication sur CoddyKit est structuré pour les débutants jusqu'aux apprenants avancés, donc tu peux commencer ici ou depuis le début et avancer à ton rythme. Ceci est la leçon 2 sur 4.

Combien de temps prend la leçon « Listes noires et listes blanches de JWT » ?

La plupart des leçons CoddyKit prennent environ 5–10 minutes. Chacune est courte et interactive, tu progresses régulièrement et tu repiques exactement où tu t'es arrêté sur le web et l'app.

Peux-tu écrire et exécuter du code dans cette leçon Spring Security 6 & JWT Authentication ?

Oui. Chaque leçon Spring Security 6 & JWT Authentication inclut un éditeur de code intégré, tu écris et exécutes du vrai code directement dans ton navigateur et tu reçois des retours IA instantanés — aucune configuration locale requise.

Toutes les leçons de ce cours

  1. JWT à courte durée de vie et cycle d’actualisation
  2. Listes noires et listes blanches de JWT
  3. Considérations de performance des JWT
  4. Mise en cache de la validation des jetons à grande échelle
← Retour à Spring Security 6 & JWT Authentication