search "token" what you see in header" is mostly 2017-2018. Didn"t you use cookie for authentication information in the past? If because cookie is not secure, cookie can set same-site to prevent CSRF attacks and httpOnly to prevent cookie hijacking attacks. If users prohibit cookie, is it not the kind of prompt that "this website needs to open cookie"?