The reasons for these decisions would go a long way to addressing the concerns bitdeveloper has, too.
The reasons for these decisions would go a long way to addressing the concerns bitdeveloper has, too.
It's a React + Redux front end with Hapi + Sequelize backend. It uses JWTs in local storage for authentication (that decision will take some defending since it most applications should store it in a cookie) and sometimes uses single uses JWTs for things like email verification. I'm planning to write up how we do Google Login, password based signup and login including email verification and initial load decisions tree for dashboard or login page.
Why do you think that most application should store JWT token in the cookie? Both approaches have their pros/cons.
This does a better job that I'm going to try for in a HN comment: http://cryto.net/~joepie91/blog/2016/06/13/stop-using-jwt-fo...