3 ms·
Well, one argument against cookie based sessions is that they get send automatically which opens a large attack vector for CSRF. (yes, you can store JWTs in co
by JepZ 8y ago
Well, one argument against cookie based sessions is that they get send automatically which opens a large attack vector for CSRF.
(yes, you can store JWTs in cookies too, but that is kinda uncommon)
- mythz 8y agoStoring JWT's in a HttpOnly Secure Cookie is common and recommended for Web Apps. https://stormpath.com/blog/where-to-store-your-jwts-cookies-vs-html5-web-storage#where-to-store-your-jwts https://stormpath.com/blog/where-to-store-your-jwts-cookies-...