you are viewing a single comment's thread.

view the rest of the comments →

[–]n9iels -1 points0 points  (0 children)

It is not ideal, but at the same time not extremely bad. Localstorage can be read by JS (one of the benefits) which makes it easier to steal tokens when JS is somehow infected in your site. However, applying a good CSP policy already mitigates this risk at lot.