Похожие чаты

TLDR : i'm building a third party api and i

want to be sure when a request comes from a domain(client side of that domain) , the request is actually from that domain and not faked.

hello , in systems like google ad sense in which the scenario is an advertisor registers an "ad" and people can come and register their applications or websites so they can load the appropriate "ad" and earn some money.
typically an api key is given to the app owner so they can use it in their application , i'm building a similar system to google ads in which people use my api to load some stuff in their application. but the thing is , api key will be used in "client side" meaning in browser of users of the "app owner's application". so it can be easily leaked or even worse , the app owner itself spam the api key with a script or something.
so in my server , when a request comes , how can i make sure that this request is coming from domain "example.com" that is registered in my database and that api key was built for ? as far as i know i can't just rely on http headers since they can easily be manipulated !
at first i thought tls takes care of but gpt said otherwise

4 ответов

16 просмотров

fixed IP address?

mohammad- Автор вопроса
Roman Sharkov
fixed IP address?

nope , since the api key will be used in browser (users of my customers) , the ip will vary

mohammad
nope , since the api key will be used in browser (...

then it's not a "domain" the request is coming from. I thought your clients are servers of other people. But in that case - there's no way.

AdSense does not have a protection against the scenario you describe either, they just rely on the headers of clients, and clients can see AdSense API keys

Похожие вопросы

Обсуждают сегодня

А кто-то пробовал, уезжая из Эстонии получить э-рез и продолжить вести предпринимательскую деятельность внутри Эстонии, используя свой OÜ?
Lalalashechki Lalala
62
Если у меня есть такой класс: Object = {} function Object:new(a_name, a_transform, a_color, a_mesh, a_material, a_shader, a_textures) local private = {} private.n...
Cuarno Vile
4
I'm new at Monero and I'd like to ask you all - why are you in Monero? I know about privacy but what do you expect to happen in the next years, decades that Monero will make i...
Konrad
18
Is Kadena onto something special? No one really knows. Good luck!
Bright Uncle Stephen EqualBet
40
я не магистр хаскеля, но разве не может лейзи тип конвертнуться в не-лейзи запросив вычисление содержимого прям при инициализации?
deadgnom32 λ madao
100
At which price point will BCH, an ASIC mined coin, be succeptible to reorg attacks because of low hashrate? $10? $1? $0.1? $0.01?
Kishniev
18
Гайз, кто-нибудь пробовал запустить probe-rs под камень, которого нет в probe-rs? Мб есть какой-нибудь пример у кого... Через target-gen попробовал сгенерировать chip-descript...
Максим Смирнов
2
зачем же переименовывать ? чтобы кол-во участников возросло или вдруг IBM от этого снова на свифте начнет кодить ? Я не понимаю что страшного в том что свифт гавно, если это т...
Oleh Nerzh
10
2 years ago I bought akt on Bittrex, at that time it gave a withdrawal option to the polygon network. I have read in this chat and they say that akt is not in polygon but if ...
TW
13
здравствуйте. совершаю вот такую вещь: strcpy(line, (char)current_number); где current number — неподписанный шорт, line — массив чаров. ругань следующая: main.c:29:30: error...
Roberto's Ширгозиев
13
Карта сайта