Authentication with AngularJS, session management and security issues with REST Api WS
If you talk to the server via https, you don’t have a problem with replay attacks. My suggestion would be to leverage your server’s security technology. For example, JavaEE has an out-of-the-box login mechanism, declarative role-based protection of resources (your REST endpoints) etc. These are all managed with a set of cookies and you don’t … Read more