DEV Community

Discussion on: Should save acees token in local storage?

Collapse
 
jamesmh profile image
James Hickey

In this scenario, an httpOnly cookie is probably best. Otherwise, you leave the potential of the JWT/token being read on the client by a script, etc.

Collapse
 
rmirandasv profile image
Ronald

You are right! After reading more about these finally understand that storing token in local storage it's a security issue!!