codex-team / codex-team/notes.api
Improve auth security
Open
- Dominant language
- TypeScript
- Stars
- 4
- Forks
- 2
- PR merge metrics
- No merged PRs in 30d
Description
We need to store refresh token in http-only cookie to prevent stealing it from LocalStorage by any script (for, example Editor tool from marketplace)
See https://gist.github.com/zmts/802dc9c3510d79fd40f9dc38a12bccfc
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.