As we all know by know storing JWT tokens (or any other auth token) in local storage is not a good idea (see: https://dev.to/rdegges/please-stop-using-local-storage-1i04)
I am now building a SPA that will be used in a whitelabel setup by default. Meaning that this SPA will be served from acme.com, example.com, bla.com etc.
I however cannot whitelabel our API (that issues the Auth cookies with a JWT inside) due to CORS.
How would I be able to approach this?
Many thanks in advance;