Skip to content

[MEDIUM] [Security] JWT Stored in LocalStorage #177

@bigtcze

Description

@bigtcze

Severity: Medium
Description: The JWT access token is stored in localStorage via Zustand persist middleware. This makes it vulnerable to theft via XSS.
Complexity: 5
Permalink: https://github.com/bigtcze/noteer/blob/main/frontend/src/stores/authStore.js#L206

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions