microscopic-answer-24504
08/24/2022, 7:04 AMhigh-optician-2097
high-optician-2097
alert-scooter-7558
08/24/2022, 7:13 AMsessionStorage
and Web Workers would be vulnerable, too, wouldn’t they? Basically, when XSS is possible, you’re screwed anyway 🙂high-optician-2097
alert-scooter-7558
08/24/2022, 7:51 AMhigh-optician-2097
alert-scooter-7558
08/24/2022, 7:52 AMproud-plumber-24205
08/24/2022, 9:18 AMStoring secrets within the memory of a Web Worker offers the same security guarantees as an HttpOnly cookie: the confidentiality of the secret is protected. Still, an XSS attack can be used to send messages to the Web Worker to perform an operation that requires the secret. The Web Worker will return the result of the operation to the main execution thread.