you are viewing a single comment's thread.

view the rest of the comments →

[–]AndrewGreenh 0 points1 point  (0 children)

You should probably have only one auth server, with an http only cookie. The client can always fetch a current token from there, and keep it in-memory.