3 ms·
Using xss one might target login form and steal username/password instead of a token. So I do not see argument here against jwt. Sure the xss will have to be mo
by marius_k 3y ago
Using xss one might target login form and steal username/password instead of a token. So I do not see argument here against jwt. Sure the xss will have to be more sofisticated(?)
- aidos 3y agoI’m not arguing for / against any specific technology. I’m saying that relying on a lack of security flaws in one layer isn’t a great idea.