I want to use the most secure method to store my logged in users session in a cookie. the backend is built on Django & DRF, so I'm choosing between the simplejwt plugin for token auth or djangos default SessionAuth. the frontend isnt SPA, but will eventually have a mobile app as well. so I've been leaning towards token auth, storing them in httpOnly cookies with a short life. but at that point, i wonder if I'm essentially just going about session auth in a roundabout way?
is one better than the other (in terms of security) for this application?