Hacker News new | ask | show | jobs
by bastawhiz 475 days ago
It's only necessary to store the login token if your backend is on a different origin than your SPA is served from. It's not especially hard to avoid this.