7 ms·
Most of this article seems to be against having browser JavaScript store tokens and inject Authorization headers, which you are free to avoid if you don't want
by giaour 5y ago
Most of this article seems to be against having browser JavaScript store tokens and inject Authorization headers, which you are free to avoid if you don't want to use them. JWT is just a token format, you can set it as an HTTPS-only cookie and have your server read it from there. Stateful vs. stateless is orthogonal to how the token gets handled by the client and sent back to the server.