Is it secure to store user's session id in localStorage? On w3.org site, they say
User agents must raise a SECURITY_ERR exception whenever any of the members of a Storage object originally returned by the localStorage attribute are accessed by scripts whose effective script origin is not the same as the origin of the Document of the Window object on which the localStorage attribute was accessed.
So does this mean localStorage could be used for sensitive data?
See Question&Answers more detail:os