About this question
I am (partly) following a tutorial to develop a cordova app, based on angularJS. The author stores the refresh token in local storage, which was said to be very bad practice in one of the comments on that same tutorial. This is confirmed in another stackexchange question. Best practice is then to store the refresh token in a secure HttpOnly cookie. OWASP also mentions this as a guideline, and again they argue to use cookies, which is not possible in a native app.
Now, I can see why it is bad practice when the app is available through the browser, but if I 'phonegap' the app (so that it becomes a native one) is it then also still bad practice to store the refresh token in local storage?
If so, where should I store the refresh token then, as cookies do not exist in 'native' apps?