Where should a browser SPA store a JWT, and what is the XSS versus CSRF tradeoff?
PICTURE THIS: A SENTENCE BECOMES TOKENS
The model does not read letters like humans. It reads these pieces, then predicts the next one.
Simple meaning
localStorage is easy for XSS scripts to steal.
WHY — Auth instead of guessing?
Why interviewers care about Auth:
contrast on Auth, not two memorised paragraphs.
the developer, then one case where picking wrong hurts.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens with tokens?
Before the model can read a sentence, it goes through these steps:
- 1localStorage is easy for
XSS scripts to steal.
- 2An HttpOnly Secure cookie
cannot be read by JavaScript, which helps XSS, but you must mitigate CSRF with SameSite and anti-CSRF tokens.
- 3For first-party SPAs, HttpOnly
cookies plus SameSite=Lax or Strict is the usual product recommendation.
- 4Context mix
Attention looks at nearby tokens together.
- 5Next token
The model scores what should come next.
- 6Decode
IDs turn back into readable text.
EXAMPLE — See it in action
Let's see how a real sentence is tokenized (tokens may vary by model):
Note: Actual tokens and IDs depend on the tokenizer (e.g., GPT, Llama, etc.).
Key takeaway
localStorage is easy for XSS scripts to steal. An HttpOnly Secure cookie cannot be read by JavaScript, which helps XSS, but you must mitigate CSRF with SameSite and anti-CSRF tokens.