Alec Aivazis edited untitled.html  over 8 years ago

Commit id: e7ba32788a92daf1a0f9f8ffb39a1aa49abe1d16

deletions | additions      

       

In a single page app, all of the decisions about what view/subview to render occurs on the client and ideally does not require a trip back to the server. client.  This means that ideally the client would be able to authenticate the currently logged in user on transitions to sensitive pages  and access its data without going back to the server. This blog post summarizes my attempts at adding an additional layer of security to my locally stored authentication information.
 information. Also, I just want to make it clear: server endpoints still need to verify the request. The client can never be trusted.