Replies: 1 comment 1 reply
-
|
hello @jjlee
Maybe not silly, but insecure! So the main reason to not use the API flows for browser applications is that CSRF protection is now missing - I think also some other (less critical) things as well.
I think this is a good blogpost that goes over the different auth options that you have and their up/downsides: https://www.ory.sh/blog/auth-and-modern-software |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Hi
I set up the server-side login flow, and then got auth in the SPA parts of my application working by means of this hack in my FE code - without using the client-side flow:
Is that a silly thing to do? If I don't mind the page reload in what is otherwise mostly an SPA, is there any security reason to not do this? Other than losing my application state, is there any non-security reason not to do this (I guess I'm thinking of giving myself a maintenance headache somehow)?
Very happy to find kratos :)
Beta Was this translation helpful? Give feedback.
All reactions