3 ms·
If you don't persist JWT in localStorage or sessionStorage, how would you handle page reloads? You'd have to rely on a session cookie and get a new JWT from yo
by api_or_ipa 8y ago
If you don't persist JWT in localStorage or sessionStorage, how would you handle page reloads? You'd have to rely on a session cookie and get a new JWT from your auth service. You'd solve XSS but get CSRF.
Storing a JWT in localstore isn't the same as storing a password in plain text. JWTs are indeed non-revocable, but they are also non-durable (ours expire after 24 hours) and cannot be renewed without a refreshToken. Most people also do not rely on JWTs to write important information (like password reset) because there are more secure alternatives for these specific use cases.
As an aside, if someone gets script access to your SPA, you're already very far up shit creek. If your user types in any sensitive information like a password to login you've lost the war. Securing the JWT is the very least of your concerns at that point.