So basically my Blazor server app does a request to the Web Api that handles the login and returns the User with the access Token.
After that I store the token in session storage or cookies for future usings and to redirect the user on the profile page with login succesfull.
My question is: How do I know that the returned Token is valid?
If someone adds a random Token to the cookies then my app automatically thinks that he is logged in and shows the profile page right? (future web-api calls should not work becouse the token is invalid corect?)
How can I avoid this? Or what I'm doing wrong here?
Every help is apreciated.