|
|
|
|
|
by netdevphoenix
181 days ago
|
|
Surely, if a script is in a position to sniff the cookie from local storage, they can also indirectly use the http-only cookie by making a request from the browser. So really not much of a difference as they will be taking over the account |
|