Users become members through the app domain. app.myproduct.com this is the url we used to sign up for the app.
After the register is completed, I need to redirect the user to the domain that he/she has determined. for example dynamic.myproduct.com
After the registration process on app.myproduct.com is completed, I keep the access token in the browser local storage.
but since the user will continue on this site dynamic.myproduct.com, when I redirect there, I lose the token
I think it is not safe to send the token as a url parameter like dynamic.myproduct.com?token=blabla
How should I configure it here? Should we manage this on the frontend or the backend?