参考文章链接:
https://medium.com/@kennch/stateful-and-stateless-authentication-10aa3e3d4986
https://medium.com/soundstripe-engineering/stateful-sessions-with-json-web-tokens-74b5c08c013e
https://zhuanlan.zhihu.com/p/164696755
反对JWT替代session的文章:
http://cryto.net/~joepie91/blog/2016/06/13/stop-using-jwt-for-sessions/