Why doesn't firebase auth support httponly cookie persistence?

Viewed 64

As I know, storing jwt tokens in local storage/session storage is not secure because it can be accessed with javascript (XSS attacks), so the secure way is to store it in httpOnly cookie. So why does Firebase auth provide every persistence method except the httpOnly one?

0 Answers
Related