logoalt Hacker News

someonebaggy • yesterday at 2:32 PM • 2 replies • view on HN

I store my session token in a cookie, which is even worse because it's sent with every request.


Replies

SahAssar • yesterday at 2:49 PM

It's not. The cookie only gets sent to the domains/servers you specify and is not accidentally exposed via browser history or copying a link.

bsharper • yesterday at 2:46 PM

Not in a URL generally, and if it is the only people who can see the full URL are the receiver and the sender if HTTPS is properly enabled.