So after researching the best practices of authentication/security, it seems like storing the JWTs created by the backend in the localStorage is not secure, and thus, HTTP C