|
|
|
|
|
by adrr
980 days ago
|
|
Terrible article. JWTs can be stored in cookies giving you httponly and samesite. If you have XSS vulnerability, what you store your JWTs or if you use JWT do sessions is the least of your concern. Every request to the domain still has cookies attached even with httponly set, that includes all the AJAX initiated requests. HTTPonly just prevents javascript from reading the cookie. It just prevents cookie theft. |
|