|
|
|
|
|
by Aldipower
980 days ago
|
|
Just do not store JWTs in LocalStorage or any JavaScript accessible location.
Use secured httpOnly cookies.
Validate the JWT on server-side _stateless_. No need for a database. This idea is so good and it works! Just follow best security practice. If you don't, it is not the fault of the JWT. Bad blog article.. Yes, things like Keycloak and such follow _bad practice_. Still not the fault of JWT. |
|