Additionally, cookies can be marked as http only or even as secure, making it very hard to lose the token by virtue of a fire sheep like, or even just XSS attack.
For that reason, I personally would prefer a site using (session) cookies to one hacking it via DOM storage any day.
And finally, depending on the store you might want to persist the shopping cart between visits- likely across machines. Thus, the cart should be stored on the server and not in DOM storage.