Hacker News new | ask | show | jobs
by infotogivenm 1208 days ago
It’s pretty terrible that they even allow public access to these gateways, let alone default to it. At a very bare minimum some sort of origin header checks should be done. Who in their right mind would want to pay an exorbitant rate to put a frontend-specific JSON-RPC API out on the public internet to be abused for free by other sites?