Please do not report sensitive vulnerabilities through public GitHub issues.
Contact email address: lic.ricardo.nm@gmail.com
This repository is a starter/reference implementation. It does not promise enterprise support, guaranteed response times, or managed incident handling.
The current frontend stores access and refresh tokens in localStorage. This keeps the example simple and avoids cookie-based CSRF as the primary concern, but it increases exposure if an XSS vulnerability exists.
For real public deployments, migrate refresh tokens to HttpOnly, Secure, SameSite cookies and keep access tokens in memory. Review CORS, CSP, rate limits, logs, dependency updates, PostgreSQL backups, Redis availability, and secret rotation before operating this as a public service.