Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yours is a good solution, and effectively blocks the attack mentioned in this article. From a REST purity standpoint, it's "unclean" to require all API calls to be POSTS, but, hey, life is short.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: