Skip to content
Discussion options

You must be logged in to vote

hey @ornithophile

yes we currently store the jwt in local storage, during early discussions we decided that if malicious JS was able to run inside the page it would also be able to access these values via supabase-js's in memory store, however I'm aware certain frameworks like react may have some protection here. We're definitely open to discussion on this one, if you have some ideas feel free to open an issue inside https://github.com/supabase/supabase-js

I'm not sure about the Svelte example specifically, maybe @kiwicopple can add some insights there

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@jake-edgenaut
Comment options

Answer selected by jake-edgenaut
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants