Quantcast
Channel: Security
Viewing all articles
Browse latest Browse all 4737

OAUTH-Identity server4-JWT cookie issue

$
0
0

Hi Team,
We are planning to use Identity server for our company Authentication and Authorization. My company security analyst have following questions.
1.He told that as part of security (GDPR) we should not store the JWT token in Cookies because it is vulnerable to CSS (Cross site scripting) or CSRF (cross-site request forgery).
2.Is it possible to avoid cookies in Identity server?
3.What are all the security measures need to have if we have to use cookies?


Viewing all articles
Browse latest Browse all 4737

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>