Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"Pro: JWT is secure"

Yes, but I see a lot of implementations where the token is sent to JavaScript and is stored there.

It's best to store it as secure cookie (HttpOnly) so JavaScript cannot access it.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: