3 ms·
yup. You didn't imply it but just in case -- this token shouldn't be the same as session token. Session tokens should be `HttpOnly`, so that we don't even expos
by smagin 2y ago
yup. You didn't imply it but just in case -- this token shouldn't be the same as session token. Session tokens should be `HttpOnly`, so that we don't even expose it to javascript
- blincoln 2y agoThe HttpOnly flag isn't really practical in modern web apps where so much logic runs in JS in the browser and makes requests to APIs. It's a leftover from an earlier era of web app architecture. If it can be enabled without breaking something, sure, its a good idea, but unless your app is 2000s-era ASP.NET code or CGI script, preventing browser-side JS from accessing the session token will probably break something.
- Macha 2y agoRight, but if you're doing a SPA, your SPA makes the login call and stores a copy of the session token in local storage, which unlike a cookie isn't automatically sent on any request, never mind cross-origin ones. Doesn't prevent against XSS of course, but then that's what CSP is for.
- bastawhiz 2y agoIt's only necessary to store the login token if your backend is on a different origin than your SPA is served from. It's not especially hard to avoid this.
- smagin 2y agoYou shouldn't need your session token in JS, you can specify your fetch requests to include cookies, and you can setup CORS to allow that.