(no title)
voidUpdate | 4 days ago
Can't you just run up a huge bill for a developer by spamming requests with their key? I don't see how this wasn't always an issue?
voidUpdate | 4 days ago
Can't you just run up a huge bill for a developer by spamming requests with their key? I don't see how this wasn't always an issue?
michaelt|4 days ago
Not perfect protection of course - an attacker could spam requests with all the right headers if they wanted to - but it removes one of the big motivations for copying someone else's API key.
[1] https://docs.cloud.google.com/api-keys/docs/add-restrictions...
voidUpdate|4 days ago
chinathrow|4 days ago
joking|4 days ago