Question about security on .NET core 2.1 without using cookies
So in a web app made using .NET core 2.1 and Jquery, sensitive information is stored in a cookie.
This is a security problem because that means all a user has to do is change the value of a cookie and be able to access restricted things.
in .NET core 2.1 and jquery, how can I create some sort of session variable or something that is hidden from the client?
or if that's not possible, is there another more secure method I can implement?
Any help would be appreciated.
0 comments:
Post a Comment