Tosin Bee retweetledi
Tosin Bee
1.2K posts

Tosin Bee
@Vhic_mar
OLUWATOSIN!!!! Jesus baby❤️|backend developer-JavaScript|Typescript|football lover|Fashion designer https://t.co/1ybYsOJlTb
Lagos, Nigeria Katılım Aralık 2022
1.2K Takip Edilen724 Takipçiler
Tosin Bee retweetledi
Tosin Bee retweetledi

Tech will humble you small 😅
One day you’re confident, next day you’re googling basics again.
Normal normal. Growth is not a straight line.
#hngtech #hnginternship #hngi14
English
Tosin Bee retweetledi

@developerBolu It’s good to see all you guys comment…I was able to pick one or two good/ideal practice as backend dev
English
Tosin Bee retweetledi

Hello everyone pls make this dream come through. Thanks for the opportunity @germanlang25 🥹🙏🏽

GBOLAHAN 🪬@gbolaha_n9
@germanlang25 Can I have this kinda opportunity too ? It’s being my dream to be fluent in German and aspiring to work in Germany soon 🙏🏽
English
Tosin Bee retweetledi

I pray this goes viral 🙏🏾
I sell cassava biscuits for a living
It gets to the end user at N200
A carton contains 50 sachets
I am looking for distributors all over Nigeria
Pls WhatsApp 08084002862
If you want to buy and taste you can buy on our website comeagainfoods.com

English

@1FineBreed Yeah…it’s also very much important that the secret rotates in every refresh
Thank you…I’m trying to learn best practices.
English

@Vhic_mar Sending tokens in headers over https should be secure
Unique secrets for tokens is like JTI invalidation strategy
It works safely if the secret rotates on every refresh; a long-lived per-user secret defeats the point because a stolen refresh token can be reused indefinitely.
English

The approach i use before which I feel is less secure is that
Every user token is signed with the same secret key and if someone steals one refresh token,they might try to reuse it.
The approach I just learnt is that
Every user gets their own secret key generated dynamically
Tosin Bee@Vhic_mar
I’ve always sent my refresh token in the header even though I knew my approach isn’t fully secure but today I learnt a safer approach which is When a user logs in, I create a session key to be stored in the database and then I combined the refresh token secret and the session
English

@docikenna I’m never said token isn’t safe in headers….refresh token which is actually used for token renewal can be more secured by using a per user Dynamic refresh Token secret…just tell me you don’t understand my concept and I will explain to you again what I meant
English











