Does securing a REST application with a JWT and Basic authentication make sense?
Assuming 100% TLS for all communication – both during and at all times after login – authenticating with username/password via basic authentication and receiving a JWT in exchange is a valid use case. This is almost exactly how one of OAuth 2’s flows (‘password grant’) works. The idea is that the end user is authenticated … Read more