duansha7025 2013-02-11 04:58
浏览 52

通过限制请求源来保护REST API

I am about to create a REST API that would serve its resources to a mobile apps, these includes iOS & Android smartphones.

Now I am concern of limiting my API to serve only request coming from apps, that means if the request is done via browser then I should deny it. The reason for this is I am concern regarding the XSS attack and such.

Am I wrong in what I am thinking now? If no, then how should I tell that the requestor is coming from an App?

  • 写回答

1条回答 默认 最新

  • douyou2368 2013-02-11 05:24
    关注

    You are spot on and securing REST endpoints is very essential to ensure that you authenticate/authorize/control requests to your server resources.

    Here is a thread that discusses some best practices: Best Practices for securing a REST API / web service

    评论

报告相同问题?

悬赏问题

  • ¥15 keil的map文件中Image component sizes各项意思
  • ¥30 BC260Y用MQTT向阿里云发布主题消息一直错误
  • ¥20 求个正点原子stm32f407开发版的贪吃蛇游戏
  • ¥15 划分vlan后,链路不通了?
  • ¥20 求各位懂行的人,注册表能不能看到usb使用得具体信息,干了什么,传输了什么数据
  • ¥15 Vue3 大型图片数据拖动排序
  • ¥15 Centos / PETGEM
  • ¥15 划分vlan后不通了
  • ¥20 用雷电模拟器安装百达屋apk一直闪退
  • ¥15 算能科技20240506咨询(拒绝大模型回答)