Local storage is convenient, not a secure vault
Anything in browser storage is readable by any script running on that page.
Which means a single cross-site scripting flaw hands over whatever you kept there, including tokens. It has no protection equivalent to cookie flags that keep values away from scripts. It is a convenient place for preferences and a poor place for anything that grants access.
More on Browser security
- Same-origin policy limits which pages can read each otherSame room, different desks
- CORS relaxes browser reading rules, not authenticationA propped hatch, not a checkpoint
- SameSite cookies reduce some cross-site request risksSome journeys, not every journey
- Browser extensions inherit powerful visibilityEverything passes under it
- Content Security Policy constrains script sourcesOnly from the addresses you wrote down
- Clickjacking hides the real control beneath the clickPressed here. Answered there
