In an attempt to secure a backend using JWT token over cookies.
It is not clear to me what data is safe to store inside the token/cookie.
for example in the specific case where a check of parameters like policy role, and user license type is needed.
will it be safe to store them inside the JWT token?
OR.
Store only the user_id and get a fresh data from the storage (DB/memcached)?
Thank you