Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
stytchthrowaway
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
stytchthrowaway
4y ago
That's really surprising, thank you for following up long after this post has been flagged. That snippet certainly shows the refresh token is accessible client-side. I remain shocked that an auth company CEO would push a solution witho
2.
▲
by
stytchthrowaway
4y ago
Of course, I am not concerned that a 5 minute JWT is not HttpOnly. I did not intend to imply that. However, I am concerned that the refresh mechanism is also not HttpOnly. Firebase storing access tokens in client-side storage is an exam
3.
▲
by
stytchthrowaway
4y ago
I signed in to stytch.com and see a cookie called "stytch_session_jwt" that is not set with HttpOnly. It appears to refresh against https://stytch.com/web/sdk/sessions/authenticate with a Basic auth