I\'m working on a Web application that uses OAuth2 for users to login. I\'m a little bit confused now about how I should store refresh tokens. Putting them in a cookie and s