-
Notifications
You must be signed in to change notification settings - Fork 25.2k
Open
Description
Description
Given (for example) Damien's remark at #30421 (comment) and the sentiment expressed by Lock in Should you use the .NET 8 Identity API endpoints?, along with our own comments in the WASM+Identity article that ...
We recommend using cookies for browser-based apps instead of tokens because the browser handles cookies without exposing them to JavaScript.
... I'm not sure what, if any, additional remarks or different remarks the PU would like to make about bearer token use for the Auth lib/MSAL.js. This issue is a placeholder for at least a review of the guidance in the following articles ...
- Secure ASP.NET Core Blazor WebAssembly article
- Client-side/SPA security of sensitive data and credentials section
- Authentication library section
- Token auth section of Standalone WASM w/Identity article
Page URL
https://learn.microsoft.com/en-us/aspnet/core/blazor/security/webassembly/?view=aspnetcore-8.0
Content source URL
Document ID
8670b314-460d-3194-c53b-9a44f39c6b2a
Article author
Metadata
Metadata
Assignees
Type
Projects
Status
P0/P1 - High Priority