4 ms·
Authentication: Bearer headers This avoids most cross site scripting attacks
by koblas 6y ago
Authentication: Bearer headers
This avoids most cross site scripting attacks
- donatzsky 6y agoAre we talking jwt-style bearer tokens? They have their own issues. Better to have the auth server issue a single-use token that gets exchanged for a properly scoped session cookie on the app (sub)domain. Edit: Of course, then you also need some sort on central session storage, to properly deal with logging out.
- XCSme 6y agoBut where do you store those? Those have to be sent with each request.
- 411111111111111 6y agoThese are usually really short lifecycle, so they're usually just saved in a variable or session storage. A refresh often just gets a new one, as they're usually valid for 5 mins or even less.