Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What does this do?
This removes the use of local storage to save auth tokens. Tokens are now only stored in memory. In browser usage, this means that each browser window/tab that is opened must retrieve its own token, instead of using a locally saved one. (Note that this doesn't necessarily mean that the user needs to enter their credentials for each window/tab; as long as there is a valid session with the services layer, the token retrieval is transparent.)
Why are we doing this? (with JIRA link)
This improves security, since browser local storage is vulnerable to XSS attacks.
How should this be tested? Do these changes have associated tests?
Sign in/sign out should continue to work.
Dependencies for merging? Releasing to production?
None
Has the application documentation been updated for these changes?
n/a
Did someone actually run this code to verify it works?
@ray-lee ran this locally.