logoalt Hacker News

sothatsityesterday at 11:35 PM1 replyview on HN

Could the proxy place further restrictions like only replacing the placeholder with the real API key in approved HTTP headers? Then an API server is much less likely to reflect it back.


Replies

tptacekyesterday at 11:59 PM

It can, yes. (I don't know how Deno's work, but that's how ours works.)