Ismayil Khayredinov
1 min readSep 13, 2019

--

It’s no different from cookies, I suppose. If you manage to inject XSS - nothing is safe client side. Do you have an alternative? Where should we store session/user information?

My approach to JWT tokens is to make them short-living and refresh often: not 100% safe, but at least most tokens would have expired by the time the attacker manages to make use of them.

--

--

Ismayil Khayredinov
Ismayil Khayredinov

Written by Ismayil Khayredinov

Software engineer who combines optimism with pessimism to build robust and idiot-proof solutions

Responses (3)