logoalt Hacker News

panziyesterday at 2:47 AM1 replyview on HN

> - Your Discord session cookies and token could be stolen, leading to a complete account takeover.

Discord uses HttpOnly cookies (except for the cookie consent banner).


Replies

compootryesterday at 11:15 AM

tokens are stored in localStorage, which is accessible by JS

show 1 reply