Session-Handling: Store JWT in cookie, not in local storage
andreas-hellmann opened this issue · 0 comments
andreas-hellmann commented
If JWT is placed in cookie, it's easier to load resources (e.g. avatars) by browser means.
Don't forget to activate CSRF in angular.