I think you are correct in suggesting that state is still vulnerable, but it is less vulnerable than web storage because of it’s app-specific nature. This is outlined by one of our senior support engineers here:
dan.woda
7
Related topics
| Topic | Replies | Views | Activity | |
|---|---|---|---|---|
| Which is the best way to store the auth0 token for a web app | 7 | 13853 | September 2, 2019 | |
| React-native-auth0 useAuth0 hook vs class | 2 | 1628 | September 10, 2024 | |
| Correct pattern for memory storage of jwts in react graphQL | 2 | 3387 | August 26, 2019 | |
| Securing React application with in-memory JWT token | 2 | 8090 | May 25, 2022 | |
| Using auth0 outside of React Components | 16 | 13255 | December 29, 2020 |