Join Nostr
2026-01-18 05:11:40 UTC
in reply to

Mitch Downey :pci: on Nostr: nprofile1q…rtsmm yeah that sounds right. The exploit in that case is limited to ...

yeah that sounds right. The exploit in that case is limited to only that specific browser though, since the server has to grant the httponly status to that device. Without httponly, the JWT value could be extracted and set in a different client/device and used freely from there.