Comment by sothatsit

Comment by sothatsit 4 hours ago

1 reply

Could the proxy place further restrictions like only replacing the placeholder with the real API key in approved HTTP headers? Then an API server is much less likely to reflect it back.

tptacek 3 hours ago

It can, yes. (I don't know how Deno's work, but that's how ours works.)