> Then, store the token in a secure cookie. It's way more secure than moving a token into the browser, where a dependency vulnerability could get access to it.
Cookies are still in the browser so what difference are you specifically addressing or advocating