3 ms·
Cross site scripting can exfiltrate an auth token stored in local storage. An HttpOnly cookie cannot be stolen this way, and with SameSite=strict, CSRF is not a
by Null-Set 6y ago
Cross site scripting can exfiltrate an auth token stored in local storage. An HttpOnly cookie cannot be stolen this way, and with SameSite=strict, CSRF is not an issue.
- IgorPartola 6y agoIf I am running code on your site as another user, I don’t really need to steal you auth token. But that is true. Which is why browsers should expand support for authentication to provide things like public key authentication, credentials/personas storage, etc. At the very least, an API to store auth tokens (and just auth tokens). Better yet, a standard login UI for logging into any given website. Even better, public key auth so that instead of logging in by typing in a username and password, you would select which persona you use from a drop down and passwords aren’t a thing. Of course that would require a robust and secure mechanism for syncing the personas/keychains across different devices and browsers.