gpt4 book ai didi

html - 可以将 session ID 存储在 localStorage 中吗?

转载 作者:技术小花猫 更新时间:2023-10-29 12:36:02 25 4
gpt4 key购买 nike

将用户的 session ID 存储在 localStorage 中是否安全? ?在 w3.org site , 他们说

User agents must raise a SECURITY_ERR exception whenever any of the members of a Storage object originally returned by the localStorage attribute are accessed by scripts whose effective script origin is not the same as the origin of the Document of the Window object on which the localStorage attribute was accessed.

那么这是否意味着 localStorage 可用于敏感数据?

最佳答案

httpOnly cookie 提供了 localStorage 不提供的 XSS 防御层:

  • httpOnly cookie 无法从 [潜在恶意] JS 访问。
  • localStorage 可从 JS 访问

session ID 应存储在 httpOnly secure cookie 中。

关于html - 可以将 session ID 存储在 localStorage 中吗?,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/7604122/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com