angularjs - c# security issue with user Id being stored in browser -
i have wcf api serves data site's users (angular build). every time user connects site, returning client token (jwt encrypted user id) being stored client in local storage, , being sent client server in order server know user is. issue is feels security breach. other user can copy token , implement on browser let him impersonate user. doing wrong? should different please?
what talking called session hijacking.
there multiple solutions prevent don't think solution works 100% see link more info: what best way prevent session hijacking?
Comments
Post a Comment