Right now I am storing the user's access tokens in localStorage. I'm using reactJs. I store it by doing this in the parent component:
if (window.localStorage.hasOwnProperty('spotifyToken') === false){
const params = this.getHashParams(); //tokens saved here
const token = params.access_token;
window.localStorage.setItem('spotifyToken', token);
}
else {
spotifyApi.setAccessToken(window.localStorage.getItem('spotifyToken');
}
It seems like an ugly way of doing this and localStorage may have a possibility of being not secure. What are some better alternatives? Or is this decent enough to go through with?