Pekes317

Hi, I would agree with a lot of the points made because like you said if someone is able to inject / run JS on the front-end of the app there definitely big issues already in play. Also, either localStorage or cookies can be done insecurily. I find it interesting that no one seems is talking about sessionStorage unless it assumed to be included with localStorage since they are similar in their access. But I would agree that sessionStorage has the benefit of being cleared on new tab.