어디에 넣을까?

만약에 http only cookie에 access, refresh 둘 다 넣으면 같은 보안강도인데 의미가 있나?

https://auth0.com/docs/secure/tokens/refresh-tokens/refresh-token-rotation#automatic-reuse-detection

https://oauth.net/2/