pixelmund / svelte-kit-cookie-session

⚒️ Encrypted "stateless" cookie sessions for SvelteKit
MIT License
182 stars 11 forks source link

Secure to pass sensitive session data to page? #59

Open johnnypea opened 1 year ago

johnnypea commented 1 year ago

Please, is it safe/secure to pass sensitive session data to page like this?

/** @type {import('@sveltejs/kit').LayoutServerLoad} */
export function load({ locals, request }) {
    return {
        session: locals.session.data
    };
}

Or what is the recommended approach to use a "token" from session in client side requests (fetch) to external API?

Thank you.