this is for holding javascript data
Alec Aivazis edited untitled.html
over 8 years ago
Commit id: 4e1514f1847f9bae65e774dd4441abddcc64ec63
deletions | additions
diff --git a/untitled.html b/untitled.html
index 0558a2c..1a53ceb 100644
--- a/untitled.html
+++ b/untitled.html
...
In a single page app, all of the decisions about what view/subview to render occurs on the client. This means that ideally the client would be able to authenticate the currently logged in user on transitions to sensitive pages and access its data without going back to the server. This blog post summarizes my attempts at adding an additional layer of security to my locally stored authentication
information. Also, I just want to make it clear: server endpoints still need to verify the request. The client can never be trusted and performing crypto on the browser is a bad idea.
information.