Where should you store a refresh token in a browser SPA?
PICTURE THIS: A SENTENCE BECOMES TOKENS
The model does not read letters like humans. It reads these pieces, then predicts the next one.
Simple meaning
Prefer httpOnly secure cookies with tight CSRF strategy.
WHY — Security instead of guessing?
Why interviewers care about Security:
who only read docs from people who shipped.
and tied to Full Stack work.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens step by step?
Before you speak the answer, walk the interviewer through these steps:
- 1Prefer httpOnly secure cookies
with tight CSRF strategy.
- 2localStorage is easy for
XSS to steal.
- 3I explain the trade-off
in interviews instead of claiming one perfect answer.
- 4Give an example
One tiny concrete case you can say aloud.
- 5Common mistake
What juniors usually get wrong.
- 6Close
When you pick this over the alternative.
EXAMPLE — See it in action
Here's a short line you can speak, broken into clear beats:
Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.
Key takeaway
Prefer httpOnly secure cookies with tight CSRF strategy. localStorage is easy for XSS to steal.