Part 1. Introduction & Setting the cookies

Don’t judge — it’s my first post ever… But since it’s hard to find all information i’ve gathered in one place — i feel the need to share this with all who will come here from the Google’s search ;)

So, where to start… Some time ago our FE developer told me that neither the localStorage nor the cookies are the places to save a sensitive information to and we need to change the authorization…




HttpOnly cookie-based authorization setup using Symfony, Api Platform, LexikJWTAuthenticationBundle and JWTRefreshTokenBundle

