httponly cookie in react and node js based application

Viewed 630

I have one website whose frontend is React with link myaapplication.com and backend api is node Js with link api.myapplication.com. I am using JWT for authentication. I am sending token as JSON response.

My Issue is

I don't want to store these cookie in local storage or client side cookie.

How can i secure this ??

WHAT I tried

  • I passed token in res.cookie with httponly flag.
  • Using Proxy to use httponly cookie in my react app using code { ... "proxy": "http://localhost:3001" }, it was working fine

But As per document it will work only in development not in production .

Any way to make it secure in production ??

Thanks

1 Answers

In production you'll be deploying your builded app. Where your front-end will be served as static from your back-end.

Related