Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

browser: Should default to session storage #156

Open
ben-polinsky opened this issue Apr 13, 2023 · 1 comment
Open

browser: Should default to session storage #156

ben-polinsky opened this issue Apr 13, 2023 · 1 comment
Assignees
Labels
breaking change browser Related to the browser authorization security

Comments

@ben-polinsky
Copy link
Collaborator

Investigation has previously been done on defaulting to using the session store for user state, but encountered a blocker from our Identity Provider. We should double back and see if this is now possible.

@ben-polinsky ben-polinsky changed the title Should default to session storage BrowserAuth: Should default to session storage Apr 13, 2023
@ben-polinsky ben-polinsky changed the title BrowserAuth: Should default to session storage browser: Should default to session storage Apr 13, 2023
@ben-polinsky ben-polinsky self-assigned this Apr 13, 2023
@ben-polinsky ben-polinsky added the browser Related to the browser authorization label Apr 25, 2023
@ben-polinsky
Copy link
Collaborator Author

This is a safer, but more annoying default. I'm not convinced it's that much more secure for short-lived tokens.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
breaking change browser Related to the browser authorization security
Projects
None yet
Development

No branches or pull requests

1 participant