Answer the question
In order to leave comments, you need to log in
Is it correct approach to store access_token in cookie and refresh_token in session?
Is the session the most secure place to store the token and inaccessible to an attacker? What other combination can you choose?
Answer the question
In order to leave comments, you need to log in
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question