Guys, how bad is this https://supertokens.com/docs...
# support-questions-legacy
r
Guys, how bad is this https://supertokens.com/docs/thirdpartyemailpassword/common-customizations/sessions/token-transfer-method vulnerability for XSS attacks with the
Authorization
header? Could you provide a bit more info on this, or where to read on this/what to do?
r
hey @robschilder use cookie based auth instead (which is the the default for webapps)
3 Views