Skip to content

Improve auth security #237

Description

@neSpecc

We need to store refresh token in http-only cookie to prevent stealing it from LocalStorage by any script (for, example Editor tool from marketplace)

See https://gist.github.com/zmts/802dc9c3510d79fd40f9dc38a12bccfc

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions