HN
Hacker News
Top
New
Best
Ask
Show
Jobs
Comment by mrmagooey | Hacker News Reader
Parent
Full thread
mrmagooey
·
Isn't JWT a modern alternative to CSRF tokens?
View on HN
vmasto
·
It's not. If you think it is you probably store JWT unsafely instead of in an httpOnly secure cookie.
hawkweed
·
Why do you think storing JWT in secure cookie is only secure solution?
Reply on news.ycombinator.com