Is there any reason to use HTTP header authorization to send JWT token?
I was confused using authorization header and cookie.
If I use the cookie,
Server will send JWT token in cookie. (Client side will be stored in cookie).
If I use the authorization header, Server will send JWT token through header and client side will store token in local storage.
I guess both can be vulnerable to security. I’ve checked several posts, but only said that both methods are dangerous.
Please help me to understand this. Thank you.