3 ms·
You can also store a JWT in localStorage and require an additional secure signature for it within a cookie (http-only). Best of both worlds.
by shock-value 6y ago
You can also store a JWT in localStorage and require an additional secure signature for it within a cookie (http-only). Best of both worlds.
- ivoecpereira 6y agoIf doing that, why not go full-mode and store JWT in cookie with http-only flag?
- shock-value 6y agoThere are good uses for page content to know what's in the JWT (display username, show logged-in status, etc). Cookies also have stricter size limits. Additionally, cookies by themselves are uniquely vulnerable to CSRF, although I guess these days using SameSite property correctly mitigates that.
- jakelazaroff 6y agoYou can prevent CSRF attacks by simply requiring a custom HTTP header: https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html#use-of-custom-request-headers https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Re...