Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

Client side apps will be caught as well. Putting a JWT in a HttpOnly cookie is a common pattern. In fact, many people recommend this approach over localStorage for security reasons.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: