Hacker News new | ask | show | jobs
by marcosdumay 980 days ago
> What am I missing?

People using JS frontend frameworks to handle every single feature of the frontend, so that they have to let the cookie unprotected or store the token into a JS-only storage.