4 ms·
Ideally you need to use httpOnly cookies to store your JWTs too.
by yarper 10y ago
Ideally you need to use httpOnly cookies to store your JWTs too.
- zimbatm 10y agoIf the SPA is doing XHR requests then a localStorage is also an option. It has the advantage that the application can control on which requests the token is being sent, in contracts with cookies where they are sent for any requests on then domain.