I may be misunderstanding you, but I do want to reiterate: if it’s in localstorage, I will hijack user sessions on your pentest.
If there’s a use case to keep session tokens in localstorage, it’s insecure design that’s inherently vulnerable.
If there’s a use case to keep session tokens in localstorage, it’s insecure design that’s inherently vulnerable.