The REST API will be designed to accept username and password and do authentication. The HTTP method used is POST, so no caching. In addition, to ensure security at the time of transit
Here's how to do it, so you're good here.
JWT - . . cookie,
, - JWT-, , CSRF, - + cookie , CSRF. localStorage "" .
API REST HTTP . , . , ( , ) Cookies
, , .
API REST , reset cookie , , API , .
API, cookie localStorage , .
express-jwt , ": [Token]", cookie. LocalStorage API IE8, .
Edit:
XSS CSRF, .
XSS - JS, , , JWT localStorage, , JWT cookie . httpOnly cookie , AJAX . , . , , , .
JS iframes, localStorage, , , .
CSRF , HTML- , cookie. , , . JWT localStorage , .
, , cookie httpOnly , , api.domain. com + app.domain.com , JWT - .
, !