177 ms·
I’m all for replacing as much 3rd party libs with stdlib but it’s hard to look past the storing of the jwt in localStorage. Please don’t do that people. It’s ve
by pheew 6mo ago
I’m all for replacing as much 3rd party libs with stdlib but it’s hard to look past the storing of the jwt in localStorage. Please don’t do that people. It’s very easily extracted through xss attacks.
- moi2388 6mo agoA cookie is susceptible to both xss and CSRF. You ought to be protecting against xss anyway.