Hacker News new | ask | show | jobs
by aembleton 4 days ago
If the backend doesn't check the credentials then it doesn't matter if its JWT or encrypted cookies or anything else.