4 ms·
This is such an opaque response, I don't know what else could be said. If you're sending the same token to multiple websites, something feels very wrong with th
by coder543 5y ago
This is such an opaque response, I don't know what else could be said. If you're sending the same token to multiple websites, something feels very wrong with that situation. If it's all the same website, you can have multiple backends "mounted" on different paths, and that won't cause any problems with a SameSite cookie.
- szastamasta 5y agoThen you need a single point of failure that is handling session validation. Without it part of your app might work even without your sessions storage.
- coder543 5y agoYou can store a JWT in a session cookie. You don’t need a SPoF for session validation, if that’s not what you want.