Optional Practice Lab 3 of 4 · 20 min
Tokens Under Attack
Practice reasoning about who may assert what, what a JWT does and does not hide, how long a cached token should live, and which verification check stops which attack.
Covers Lesson 8 · Lesson 9 · Lesson 10
What you will practice
- Explain why minting must happen at a third party the caller does not control.
- State what a JWT protects and what it exposes.
- Trace one call through the exchange and verification flow.
- Match each verification check to the attack it prevents.
Step 1 of 7
Pass with 80% · unlimited retries
0% correct
01
Why a third party
Why can the Go service not simply sign its own tokens saying which user a call is for?