0Pricing
Spring Security 6 & JWT Authentication · 课时

JWT 黑名单与白名单

深入学习高级令牌撤销技术,包括维护令牌黑名单或白名单。

JWT 黑名单与白名单 是 CoddyKit 上的免费 Spring Security 6 & JWT Authentication 课时。 这是第 2 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Spring Security 6 & JWT Authentication 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Spring Security 6 & JWT Authentication 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

Why Revoke JWTs?

JSON Web Tokens (JWTs) are powerful for authentication, but sometimes you need to invalidate them before their natural expiry. This process is called token revocation.

  • Compromised Token: If a token is stolen.
  • User Logout: To immediately end a user's session.
  • Password Change: To invalidate all old tokens.
  • Role Changes: To force re-authentication with new permissions.

The Stateless Challenge

JWTs are inherently stateless. Once issued, they contain all necessary information for validation and don't require the server to store session data.

This statelessness is a strength, but it makes direct server-side revocation tricky. The server typically doesn't hold a list of active tokens to simply 'turn off'.

Blacklisting Explained

Blacklisting is a common strategy to revoke JWTs. When a token needs to be invalidated, its unique identifier (often the JTI claim) is added to a 'blacklist' — a list of forbidden tokens.

  • Any token whose JTI is on this list is rejected, even if it's cryptographically valid and not expired.
  • This allows you to 'undo' a token's validity.

Implementing a Blacklist

The blacklist needs to be stored in a highly available, fast-access data store. Speed is crucial because every incoming request might need to check this list.

  • Redis: An excellent choice due to its in-memory nature and support for time-to-live (TTL) on entries, which can match token expiry.
  • Database: A simple table can work, but might be slower for high-volume checks.
  • Each entry typically stores the JWT's JTI and its original expiry time.

Simple Blacklist Service

Here's a basic interface for a service that manages a token blacklist. In a real application, this would interact with a database or a caching system like Redis.

public interface TokenBlacklistService {
  void blacklistToken(String jti, long expirySeconds);
  boolean isBlacklisted(String jti);
}

JWT Filter with Blacklist Check

When a request arrives, a security filter would first validate the JWT's signature and expiry. Then, it would check if the token's JTI is present on the blacklist before granting access.

Try running this example:

import java.util.HashSet;
import java.util.Set;

// A simplified in-memory blacklist for demonstration
class MockTokenBlacklistService {
    private Set<String> blacklistedJtis = new HashSet<>();

    public void blacklistToken(String jti, long expirySeconds) {
        System.out.println("Action: Blacklisting JTI " + jti);
        blacklistedJtis.add(jti);
        // In a real app, 'expirySeconds' would set a TTL on the blacklist entry
    }

    public boolean isBlacklisted(String jti) {
        boolean result = blacklistedJtis.contains(jti);
        System.out.println("Check: Is JTI " + jti + " blacklisted? " + result);
        return result;
    }
}

public class Main {
    public static void main(String[] args) {
        MockTokenBlacklistService blacklist = new MockTokenBlacklistService();

        String userTokenJti = "user-abc-123";
        String adminTokenJti = "admin-def-456";

        // Simulate an admin token being revoked after a security event
        blacklist.blacklistToken(adminTokenJti, 3600); // Token expires in 1 hour

        // Check access for different tokens
        System.out.println("\n--- Access Checks ---");
        System.out.println("User token access: " + (blacklist.isBlacklisted(userTokenJti) ? "DENIED" : "GRANTED"));
        System.out.println("Admin token access: " + (blacklist.isBlacklisted(adminTokenJti) ? "DENIED" : "GRANTED"));
    }
}

Whitelisting Explained

Whitelisting is an alternative revocation strategy. Instead of listing forbidden tokens, you maintain a list of active, allowed tokens.

  • When a token is issued, its JTI is added to a 'whitelist'.
  • For every request, the token's JTI must be found on this whitelist to be considered valid.
  • If a token's JTI is not on the whitelist, it's rejected.

Implementing a Whitelist

Similar to blacklisting, a whitelist requires a fast, persistent store (e.g., Redis). The key difference is what you store and how you manage it:

  • Each entry typically stores the JWT's JTI, often associated with a user ID.
  • When a user logs out or changes their password, all active JTIs associated with that user can be efficiently removed from the whitelist.

Blacklist vs. Whitelist Comparison

Both strategies achieve revocation but have different implications:

  • Blacklist: Ideal for rare, specific revocations (e.g., single token compromise). Requires less storage if revocations are infrequent.
  • Whitelist: Better for frequent revocations (e.g., user logout invalidates all tokens). Can simplify session management but requires more storage for all active tokens.
  • The choice depends on your application's specific needs and the frequency of revocations.

Revocation Scenario

Consider an application where users frequently log out, and you need to ensure all their issued tokens are immediately invalidated upon logout.

Recap: Revocation Strategies

In this lesson, we've explored advanced strategies for revoking JWTs, which is crucial for robust security:

  • Blacklisting: Marking specific tokens as invalid by adding their JTI to a forbidden list.
  • Whitelisting: Only allowing tokens that are explicitly listed as active, often tied to a user session.
  • The best approach depends on your application's requirements, especially the frequency and nature of token invalidation.

Next, we'll analyze the performance implications of these techniques.

常见问题解答

「JWT 黑名单与白名单」课时是免费的吗?

是的 — 「JWT 黑名单与白名单」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Spring Security 6 & JWT Authentication 课程的其余内容,请升级到 CoddyKit PRO。 Spring Security 6 & JWT Authentication 课程共包含 4 节课。

「JWT 黑名单与白名单」这节课中我会学到什么?

深入学习高级令牌撤销技术,包括维护令牌黑名单或白名单。 你通过在浏览器中直接运行的动手代码来练习 Spring Security 6 & JWT Authentication,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 Spring Security 6 & JWT Authentication 需要有经验吗?

无需任何先前经验。CoddyKit 上的 Spring Security 6 & JWT Authentication 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 2 节课,共 4 节。

「JWT 黑名单与白名单」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 Spring Security 6 & JWT Authentication 课中编写并运行代码吗?

能。每节 Spring Security 6 & JWT Authentication 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. 短生命周期 JWT 与刷新周期
  2. JWT 黑名单与白名单
  3. JWT 的性能考量
  4. 缓存令牌验证以实现扩展
← 返回 Spring Security 6 & JWT Authentication