How Should I Securely Store User Tokens in a Full-Stack Application? #900
Answered
by
methmal99
Dilusha-Ranasingha
asked this question in
Q&A
-
|
I’m working on a full-stack app and need advice on the safest way to store user authentication tokens. Should I use localStorage, sessionStorage, cookies, or something else? I want to avoid common security issues like XSS and token theft. Thanks! |
Beta Was this translation helpful? Give feedback.
Answered by
methmal99
Nov 26, 2025
Replies: 1 comment
-
|
Use localStorage, sessionStorage and Regular Cookies. And HTTPOnly + Secure + SameSite = Strict/Lax cookies. |
Beta Was this translation helpful? Give feedback.
0 replies
Answer selected by
Dilusha-Ranasingha
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Use localStorage, sessionStorage and Regular Cookies. And HTTPOnly + Secure + SameSite = Strict/Lax cookies.