AI Features

Never Trust The Client

In this lesson, we'll see how JWTs can be used to prevent clients from tampering with data.

We'll cover the following...

As we’ve seen before, cookies that are issued by our servers can be tampered with, especially if they’re not HttpOnly and are accessible by JS code on your page.

At the same time, even if your cookies are HttpOnly, storing plaintext data in them is not ...