AOSSIE-Org / AOSSIE-Org/DebateAI

[SECURITY]: The JWT token is stored in the local-storage.

Abierto
#204 2 comentarios 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
TypeScript
Estrellas
84
Forks
198
Merge medio
2 d 19 h
PR fusionados (30 d)
30

Descripción

I just noticed that after logging in to the DebateAI, the jwt token is getting stored into the local storage, and i had heard from sources that storing the token in the local storage is not safe. But I got to know that the token's only payload is `email` but still it's not safe, I visited the auth0 official docs (https://auth0.com/docs/secure/security-guidance/data-security/token-storage#don-t-store-tokens-in-local-storage) and even they does not guide to store the tokens in local storage, due to a cross-site scripting (XSS) attack.

Image

Changes we need to get back to a secure auth -
- set `credientials: true` in frontend and CORS.
- Setting and reading HTTP-only cookies
- Correcting the CORS config.

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.