|
|
|
|
|
by airza
980 days ago
|
|
Oh fuck off.
This energy and thinking inside the appsec community (of which i am a working member) is the reason the local _pizza company_ feels the need to have a 12 hour timeout on my mobile phone. Just implement a decent content security policy and then you can have the best of both worlds: stateless backend without having the (incredibly minor) risk of having your jwt token stole on my goddamn pizza website. |
|
Your job is to solve problems. In the real world. For real people. Start doing it.