3 ms·
Why not store short lived token in a cookie as well?
by zacksinclair 6y ago
Why not store short lived token in a cookie as well?
- poxrud 6y agoBecause then you can be vulnerable to csrf attack. For example if someone tricks you into clicking www.mysite.com/api/delete-account
- deleted 6y ago[deleted]
- anaxag0ras 6y agoCSRF attacks can be prevented using same-site policy with cookies.
- poxrud 6y agoThat is true but it will not protect against all forms of CSRF, for example you'll be vulnerable if you have user generated content that's not sanitized properly. On the refresh_token cookie I have sameSite and httpOnly set.