Holding access token in localStorage

Viewed 131

Right now I am storing the user's access tokens in localStorage. I'm using reactJs. I store it by doing this in the parent component:

if (window.localStorage.hasOwnProperty('spotifyToken') === false){
     const params = this.getHashParams(); //tokens saved here
     const token = params.access_token;
     window.localStorage.setItem('spotifyToken', token);
}
else {
     spotifyApi.setAccessToken(window.localStorage.getItem('spotifyToken');
}

It seems like an ugly way of doing this and localStorage may have a possibility of being not secure. What are some better alternatives? Or is this decent enough to go through with?

0 Answers
Related