4 ms·
Of course. I've joined a company that uses nuxt with nuxt-auth, which is incapable of securely (i.e. not) storing tokens. This means access tokens are stored b
by ddek 5y ago
Of course.
I've joined a company that uses nuxt with nuxt-auth, which is incapable of securely (i.e. not) storing tokens. This means access tokens are stored by JS in cookies. So I know the app is vulnerable to XSS, but there is no way to fix it because the author of the tool doesn't think it's important.
Honestly, if developers didn't know they were releasing vulnerable apps, I'd be more concerned.
- traveler01 5y agoAt this point its more about the cost/time management. Stuff will always have errors, its just about "is it worth out time and money to fix this issue?"