alt
Hacker News
Sohcahtoa82
•
yesterday at 10:14 PM
•
0 replies
•
view on HN
HttpOnly makes it so XSS can't
steal
your token, but that won't stop XSS from
using
your token.