• PoolloverNathan@programming.dev
    link
    fedilink
    arrow-up
    2
    ·
    4 days ago

    A session token… set by JavaScript, with no secure attribute, and no domain. (and no expiry, but I think that just uses browser lifetime)