JWT
JWT Structure
Header.Payload.Signature
Header: { "alg": "HS256", "typ": "JWT" }
Payload: { "sub": "123", "name": "Alice", "exp": 1700000000 }
Signature: HMAC-SHA256(base64(header) + "." + base64(payload), secret)
JWT in Spring Boot
// Generate
String jwt = Jwts.builder()
.setSubject(userId)
.setIssuedAt(new Date())
.setExpiration(new Date(System.currentTimeMillis() + 86400000))
.signWith(SignatureAlgorithm.HS256, secret)
.compact();
// Parse
Claims claims = Jwts.parser()
.setSigningKey(secret)
.parseClaimsJws(jwt)
.getBody();
JWT Security
- Use strong secret key
- Set expiration (short-lived)
- Never store sensitive data in payload
- Use HTTPS only
Token Management
Token Lifecycle
- Generation: Create with short expiry
- Validation: Verify signature and claims
- Refresh: Exchange refresh token for new access token
- Revocation: Invalidate on logout/security events
Storage
- Access tokens: Memory or short-lived storage
- Refresh tokens: Secure HTTP-only cookies
- Revoked tokens: Redis blacklist with TTL
Best Practices
- Rotate signing keys regularly
- Implement token binding
- Monitor token usage patterns
Key Points
- Understanding JWT (JSON Web Tokens) is essential for production systems
- Always consider scalability and maintainability
- Test thoroughly before deploying to production
- Monitor performance and set up alerting
Common Patterns
- Validation: Always validate input at the boundary
- Error Handling: Use structured error responses
- Logging: Log key events for debugging
- Testing: Unit, integration, and load tests
- Documentation: Keep docs updated with code changes
Practice Problems
Design and implement a solution for JWT (JSON Web Tokens) in a backend system. Consider scalability, error handling, and production readiness.
Solution
// JWT (JSON Web Tokens) implementation
// Key aspects: validation, error handling, logging, testing
public class JWTJSONWebTokens {
// Production-ready implementation
}Identify and handle edge cases for JWT (JSON Web Tokens). What happens under high load, with invalid input, or during failures?
Solution
// Edge case handling:
// 1. Null/empty input -> validation
// 2. High load -> rate limiting, queuing
// 3. Failures -> retries, circuit breaker
// 4. Concurrent access -> locks, idempotencyWrite a testing strategy for JWT (JSON Web Tokens). Include unit tests, integration tests, and performance tests.
Solution
// Test plan:
// - Unit: 80% coverage target
// - Integration: API contracts
// - Performance: latency, throughput
// - Chaos: failure injectionQuiz
1. JWT consists of?
2. Where should JWT secret be stored?
3. What is the primary purpose of JWT (JSON Web Tokens)?
4. What is a common mistake when implementing JWT (JSON Web Tokens)?
Flashcards
Question
JWT structure?
Click to reveal answer
Answer
Header.Payload.Signature
Question
Where to store JWT secret?
Click to reveal answer
Answer
Environment variable or secret manager
Question
What is JWT (JSON Web Tokens)?
Click to reveal answer
Answer
JWT (JSON Web Tokens) is a key concept in backend development.
Question
When to use JWT (JSON Web Tokens)?
Click to reveal answer
Answer
Use JWT (JSON Web Tokens) when building production systems that require reliability, scalability, and maintainability.
Question
JWT (JSON Web Tokens) best practices
Click to reveal answer
Answer
Follow SOLID principles, write clean code, test thoroughly, document decisions, and monitor in production.
Revision Notes
Key Takeaways
- 1.JWT = Header.Payload.Signature
- 2.Payload is encoded, not encrypted
- 3.Never store secrets in code
- 4.Set short expiration times
Interview Tips
- •Explain JWT structure
- •Know JWT security best practices
Cheat Sheet
JWT
- Structure: Header.Payload.Signature
- Payload: encoded (not encrypted)
- Store secrets: env vars, secret managers
- Set expiration