Hello, I just started using supabase for authentication and noticed that it stores the jwt in localStorage. I tested firebase and it is also configured to store the jwt there if you follow the docs for Authentication State Persistence... However, I read that it would be more secure to store the jwt as a http-only cookie since localStorage is not supposed to be used for sensitive stuff (https://cheatsheetseries.owasp.org/cheatsheets/HTML5_Security_Cheat_Sheet.html#local-storage). Are there really security risks to the supabase/firebase approach?
n
Needle
03/28/2022, 5:52 PM
Hello @stefan199!
This thread has been automatically created from your message in #843999948717555735 a ``few seconds ago``.
Pinging @User so that they see this as well!
Want to unsubscribe from this thread?
Right-click the thread in Discord (or use the ... menu) and select Leave Thread to unsubscribe from future updates.
Want to change the title?
Use the
/title
command!
We have solved your problem?
Click the button below to archive it.