• @GreenKnight23@lemmy.world
    link
    fedilink
    English
    010 days ago

    yes, but those frontends are typically tied closer to the backend than a public API.

    things like CSRF can help block abuse of the back end.

      • @GreenKnight23@lemmy.world
        link
        fedilink
        English
        -110 days ago

        well that’s poor planning and why bots are such a problem.

        I know CSRF tokens aren’t a silver bullet, but doing nothing to stop them does nothing to stop them.

        • @tfm@europe.pub
          link
          fedilink
          English
          49 days ago

          CSRF protection is a security feature not bot prevention. A bot would just need to get a token first.