I have an angular2 app that authenticates through OAuth2 with password grant type. I store the session token on sessionStorage, and I need to store another data more secure, like user current roles.
I know that I can store more information in sessionStorage or localStorage, but this is easy modified by user. Although really, if the user modifies the sessionStorage, my backend is secured because check the token against user roles.
What happens is that if the user modifies his role he could see some hidden options, and i dont want this.
I think of two solutions, and i want listen some tips.
- Save the role in sessionStorage encrypted, suggestion about this? what encryptation i should use?
- Having a global service like is explained on angular docs, which is used by my navbar-component and load data on ngOnInit (because routes).
Any suggestion? Thanks.