Before and after the end of the separation, to generate the token, the token is stored in where more appropriate
1. Saved in cookies, background, and set the httponly=true,,,,,,, z as previous session mode of this kind of feeling, seems not science
2, the front end to save! But where is the front end and save,,, save cookies, front is likely to be attacked, not safe!
Your bosses, you save the token, when passing information is how to do?????
CodePudding user response:
Directly with JWT generated token need not storage, decoding
CodePudding user response: