Current best practice for CA SSO - Angular SPAs

May 25, 2017
What is the current best practice for securing script (Like AngularJS) based applications with CA SSO? We have multiple Angular applications that need to be integrated with CA SSO, that make API calls on behalf of the user. Session cookies (set to HTTPONLY) do not seem to be a good fit for these technologies. What tools in the SSO toolbag work best in these situations?




