Keeping credentials out of browser JavaScript with a BFF

Coming soon
IntermediateDifficulty: Intermediate
DeveloperAudience: Developer
Security practitionerAudience: Security practitioner
Secure accessPurpose: Secure access

Wave 4 · Implementations and alternatives · T02.10

Coming soon — this article is being prepared. Below are its question, intended outcome, and place in the story.

The question

How can you route browser requests through a BFF without exposing tokens to JavaScript?

What we will work through

Route browser requests through a BFF without exposing tokens to JavaScript.

Before you begin

Previously covered: The lifecycle of a server-side session; Inside a JWT: header, payload, and signature.

Articles

Color theme

Language

Home