Steve Pryde
Apr 16, 2022

--

If your http-only cookie is sent on every request, wouldn't XSS also be able to make its own requests, using the cookie, and have those requests appear to come from your domain?

If you're vulnerable to XSS, you're screwed either way. If you're not, then JWT is fine.

--

--

Steve Pryde
Steve Pryde

Written by Steve Pryde

I’m a Software Engineer and the creator of the Rust crate “thirtyfour”, a batteries-included Selenium client for Rust.

No responses yet