Cloud Security Labs docs!

⌘K
ServicesBlogGithub
Welcome!
Resources
Data Deletion Request
Security Awareness
Security Pages & Whitepapers
Cybersecurity Diversity Groups
Migrating AWS Accounts From One Org To Another
DNS Tools
Google Workspaces (G Suite) Security
Security Best Practices
Misc Scripts and Tools
Glossary
Bug Bounty Example
Tool List
AWS Security
AWS Security Best Practices
Identity and Authentication
Google Workspace Security
Documentation powered by archbee 
7min

JWT Security Best Practices



Do Not Store Tokens in localStorage

Document image

Source: The Complete Guide to React User Authentication with Auth0

Excellent talk on JWT Security!



Additional Resources:

  • https://auth0.com/blog/refresh-tokens-what-are-they-and-when-to-use-them/
  • https://twitter.com/sec_r0/status/1353353299689238529
  • https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/
  • https://cloudsecuritylabs.io/blog/jwt-token-security-best-practices/
  • https://fusionauth.io/learn/expert-advice/tokens/revoking-jwts/



|
Updated 19 Aug 2021
Did this page help?
Yes
No
UP NEXT
File Sharing Best Practices
Documentation powered by archbee 
|
Updated 19 Aug 2021
Did this page help?
Yes
No
UP NEXT
File Sharing Best Practices
Documentation powered by archbee