N
N
Nikita2020-07-15 22:53:25
User identification
Nikita, 2020-07-15 22:53:25

Is it correct approach to store access_token in cookie and refresh_token in session?

Is the session the most secure place to store the token and inaccessible to an attacker? What other combination can you choose?

Answer the question

In order to leave comments, you need to log in

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question