>
And I hope I never end up using any application developed this way.Slack [0] has entered the chat.
Jira [1] has entered that chat.
I could go on but I don't need to. Many web applications that people use store an unnecessarily obnoxious amount of data locally. I can only imagine how much of that is used just once or possibly even never (like images in settings windows that were never accessed).
[0]: On one instance of Firefox on one computer, app.slack.com has stored 1.9GB. On another instance of Firefox on another computer, app.slack.com has stored about 633KB. On a third instance of Firefox on yet another computer, app.slack.com has stored about 600MB.
[1]: Jira doesn't load _at all_ if you've got any secure settings enabled (like... no CORS and no cross-domain cookies and no cross-domain XHRs and ... the list goes on). So Jira loads in an incognito window in a VM. But suffice to say that its local storage is even more _fucking obnoxious_.
> Tokens stored in those storages you mention can be read by any javascript code, even third party.
I don't doubt you. But I am not a javascript developer. I'd like it if you could link to some demonstrations of how that can be abused.