Open
Description
The HTML Local Storage can be compromised because it can be read by JavaScript and the same Domain. (XSS) Use Cookies instead. They are not accessible by JavaScript.
Ref.: https://stormpath.com/blog/where-to-store-your-jwts-cookies-vs-html5-web-storage