One thing you appear to overlook: Cookies are XSS safe when marked httpOnly, and can be locked down further with secure and samesite. And cookie handling has been around much longer === more battle hardened. Relying on JS and local storage to handle token security is a fools game. – Martijn Pieters♦ Jul 22
yesterday by jeffroush
Your API-Centric Web App Is Probably Not Safe Against XSS and CSRF
The bottomline is: session storage (and local storage) isn’t safe. Any serious penetration test marks usage of web storage for authentication token as a serious vulnerability. Many banking and insurance organizations forbid web storage for this reason.
security  authentication 
yesterday by jeffroush
Handling Authentication In Vue Using Vuex ― Scotch
step by step vue2 authentication - very good! and there's a companion post setting up the express server (link to that is within this post)
authentication  vuex  vue2  vue2authentication 
yesterday by ElliotPsyIT
JSON Web Tokens -
JSON Web Tokens are an open, industry standard RFC 7519 method for representing claims securely between two parties.

JWT.IO allows you to decode, verify and generate JWT.
authentication  security  dotnet  microsoft 
2 days ago by andyhuey

