Can an authentication JWT session cookie be used as “remember me” cookie?

Viewed 36

I’m implementing an authentication system for a REST API and i’m using the following package to do so:

https://github.com/psr7-sessions/storageless

That package basically sets a JWT in a secure http-only cookie. That works fine but now I would like to implement a “remember me” system. I’ve read a couple of articles on what the best approach is and most of them advice to store a selector and a hashed value in the database in order to deal with things like timing leaks, insufficient randomness, etc. This is the article I’m referring to:

https://paragonie.com/blog/2015/04/secure-authentication-php-with-long-term-persistence#title.2

My question is: if I extend the lifetime of my JWT session cookie, would that also be a secure way to remember the user? Timing attacks won’t be an issue, because there is no database involved, the JWT is signed with a secure, long key and the cookie is set with all the appropriate settings.

0 Answers
Related