Skip to content

trandung2k1/js_security

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Cookie , Local Storage, Session Storage

I. JWT + local storage -> XSS -> use httpOnly + secure(options cookies)

<img src="invalid_link" onerror="alert(localStorage.getItem('name'))">

II. JWT + Cookie -> CSRF -> use CORS