codex-team / codex-team/notes.api

Improve auth security

未关闭
#237 0 条评论 0 个 reaction 已指派 1 人 已被 @kloV148 认领 在 GitHub 查看
主要语言
TypeScript
星标
5
派生
2
PR 合并指标
30 天内没有已合并 PR

描述

We need to store refresh token in http-only cookie to prevent stealing it from LocalStorage by any script (for, example Editor tool from marketplace)

See https://gist.github.com/zmts/802dc9c3510d79fd40f9dc38a12bccfc

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。