0Pricing
Spring Security 6 & JWT Authentication · 课时

JWT 令牌撤销策略

探索撤销已泄露或已退出登录的 JWT 的方法,例如使用黑名单和短生命周期令牌。

JWT 令牌撤销策略 是 CoddyKit 上的免费 Spring Security 6 & JWT Authentication 课时。 这是第 2 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Spring Security 6 & JWT Authentication 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Spring Security 6 & JWT Authentication 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

Why Revoke JWTs?

JSON Web Tokens (JWTs) are designed to be stateless, meaning the server doesn't need to store session information. While this offers great scalability, it presents a challenge: how do you invalidate a token before its natural expiration?

We need revocation for scenarios like:

  • User logout
  • Token compromise (e.g., stolen token)
  • User role change or account disablement

The Statelessness Challenge

A core principle of JWTs is that once issued and signed, they can be validated without needing to query a database or external service. This means a server doesn't inherently 'know' if a token has been logically invalidated.

To revoke a JWT, you must introduce a mechanism that re-introduces a form of state, allowing the server to check if a token is still considered valid.

Strategy 1: Short-Lived Tokens

The simplest and most fundamental defense against compromised JWTs is to make them short-lived. If an access token expires quickly (e.g., 5-15 minutes), the window of opportunity for an attacker using a stolen token is minimized.

This strategy often pairs with Refresh Tokens (covered in another lesson) to provide a smooth user experience without requiring frequent re-logins.

Strategy 2: Blacklisting Tokens

To achieve immediate revocation, a common strategy is blacklisting. A blacklist is a storage (like a database table or a high-speed cache like Redis) that holds the unique identifiers (JTI claims) of tokens that have been explicitly invalidated.

When a server receives a JWT, it first checks if the token's JTI is present in the blacklist. If it is, the token is rejected, even if it hasn't expired.

Implementing a Blacklist

For an effective blacklist:

  • Unique ID: Ensure each JWT has a unique JTI (JWT ID) claim.
  • Storage: Use a fast, persistent store (e.g., Redis, database table) to hold blacklisted JTIs.
  • Check: Every time a JWT is presented, validate its signature, then check if its JTI is in the blacklist.
  • Expiration: Blacklisted tokens should still have their expiry respected. The blacklist entry itself can also have a TTL (Time To Live) matching the token's original expiry, to prevent the list from growing indefinitely.

Simulating a Blacklist

Let's look at a simple Java example to understand the blacklisting concept. We'll simulate a token's unique ID and an in-memory blacklist. In a real application, the blacklist would be a persistent, distributed store like Redis.

Blacklist in Action

This code demonstrates how a token ID can be added to a conceptual blacklist and then checked for revocation. Run it to see the output.

import java.util.HashSet;
import java.util.Set;
import java.util.UUID;

public class Main {
    private static Set<String> revokedTokens = new HashSet<>();

    public static void main(String[] args) {
        String userTokenId = UUID.randomUUID().toString();
        System.out.println("User token ID: " + userTokenId);

        // Simulate token validation
        if (!isTokenRevoked(userTokenId)) {
            System.out.println("Token is valid (not revoked).");
        } else {
            System.out.println("Token is revoked!");
        }

        // User logs out or token is compromised
        revokeToken(userTokenId);
        System.out.println("\n--- Token has been revoked ---");

        // Try to validate again
        if (!isTokenRevoked(userTokenId)) {
            System.out.println("Token is valid (not revoked).");
        } else {
            System.out.println("Token is revoked!");
        }
    }

    public static void revokeToken(String tokenId) {
        revokedTokens.add(tokenId);
    }

    public static boolean isTokenRevoked(String tokenId) {
        return revokedTokens.contains(tokenId);
    }
}

Strategy 3: Whitelisting

An alternative, though less common for raw JWTs, is whitelisting. Instead of listing invalid tokens, you maintain a list of all currently valid tokens or session IDs.

When a request comes in, you check if the token/session ID is on this 'allow list'. If it's not present, it's considered invalid. This approach is more typical for traditional session management but can be adapted.

  • Every active session gets a unique ID.
  • Store these valid IDs in a database or cache.
  • Upon logout, remove the ID from the whitelist.

Comparing Strategies

Each strategy has its place:

  • Short-Lived Tokens: Essential for minimizing risk. Always combine with other strategies.
  • Blacklisting: Best for specific, immediate invalidation (e.g., logout, compromise). Introduces a state check per request.
  • Whitelisting: Useful when you need to manage a finite set of active sessions and invalidate many at once (e.g., user disabled, revoke all sessions). Requires state for *all* tokens, which can be a performance consideration for very high-traffic APIs.

Revocation Strategies Check

Which of the following are valid strategies or important considerations for revoking JSON Web Tokens (JWTs) before their natural expiration?

Lesson Summary

In this lesson, we explored how to tackle the challenge of revoking stateless JWTs. We learned that while JWTs are stateless by design, scenarios like user logout or token compromise necessitate invalidation.

Key strategies include:

  • Using short-lived tokens to minimize risk.
  • Implementing a blacklist to mark specific tokens as invalid using their JTI.
  • Considering whitelisting for managing active sessions, though less common for raw JWTs.

The most robust solutions often combine short expiry times with a blacklisting mechanism for immediate revocation needs.

常见问题解答

「JWT 令牌撤销策略」课时是免费的吗?

是的 — 「JWT 令牌撤销策略」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Spring Security 6 & JWT Authentication 课程的其余内容,请升级到 CoddyKit PRO。 Spring Security 6 & JWT Authentication 课程共包含 4 节课。

「JWT 令牌撤销策略」这节课中我会学到什么?

探索撤销已泄露或已退出登录的 JWT 的方法,例如使用黑名单和短生命周期令牌。 你通过在浏览器中直接运行的动手代码来练习 Spring Security 6 & JWT Authentication,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 Spring Security 6 & JWT Authentication 需要有经验吗?

无需任何先前经验。CoddyKit 上的 Spring Security 6 & JWT Authentication 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 2 节课,共 4 节。

「JWT 令牌撤销策略」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 Spring Security 6 & JWT Authentication 课中编写并运行代码吗?

能。每节 Spring Security 6 & JWT Authentication 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. 实现刷新令牌
  2. JWT 令牌撤销策略
  3. 安全的令牌存储实践
  4. 轮换签名密钥与密钥管理
← 返回 Spring Security 6 & JWT Authentication