DEV Community

Discussion on: How I Fixed JWT Security Flaws in 3 Steps

Collapse
 
ale_jacques profile image
Alexandre Jacques

Hi! Nice article!

Regarding #2, you're assuming that it's a browser on the client side (so that you can use a cookie). In the case of a mobile app, what would be a secure alternative not to have the token on the response body? Use a HTTP response header?

Regards!

Collapse
 
byrro profile image
Renato Byrro • Edited

Hey Alexandre, thanks for stopping by!

That's correct, the advice assumes the client is a web browser.

I don't have experience with native mobile apps at all. But I found potentially useful references:

Again. Not my area of expertise. These are just what seemed to be relevant to me from a quick web search. Use with caution! 😉

(saudações de Minas, Brasil! 😄)