Categories

Strong Stateless Sessions

#war-on-state

The long running debate between stateful sessions (Redis/database lookups) and stateless tokens (JWTs) often generates more dogma than working solutions. Having seen recurring demand in the PostGraphile and GraphQL ecosystems for clean refresh-token rotation, I wanted to cut through the noise and build an architecture that addresses the practical reality.

Strong Stateless Sessions is an open-source pattern designed to balance stateless performance with production-grade security standards. If you are operating a distributed service architecture where centralized session stores introduce undesired coordination overhead, a hardened stateless pattern may be an attractive alternative.

This approach is designed for architectures that:

  • Need to authenticate incoming HTTP requests without a mandatory database/Redis/cache round-trip on every hop.
  • Require strict browser storage safety: tokens never touch localStorage or sessionStorage.
  • Enforce modern cookie hygiene: strict HttpOnly, Secure, and SameSite flags with automated token rotation.
  • Tolerate short access-token windows (e.g., 15 minutes, configurable) in exchange for zero-state validation.
  • Eliminate the operational burden and failure domain of running a dedicated session cluster like Redis for auth alone.

Implementations & Integrations

  • Core pattern works cleanly with PostGraphile and Apollo Server.
  • Handles token refresh lifecycles seamlessly across frontend and backend boundaries.

Refresh Token Postgraphile

(Also available on Apollo Server)

Credit to the clever people who came before me, including contributors to the OAuth spec, Ben Awad, @newsiberian for merging my upstream PR for apollo-link-token-refresh

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.