4 ms·
Localstorage is prone to XSS. You can split the JWT to have parts stored in cookie and another in localstorage. Stich the two together on the server.
by solitus 5y ago
Localstorage is prone to XSS.
You can split the JWT to have parts stored in cookie and another in localstorage. Stich the two together on the server.
- jfgiogktkt 5y agoWhat's the advantage over storing it just in the cookie then, since you need to look at it anyway, and since the localstorage storage half is useless on it's own (thus not useful from JS)?