Hacker News new | ask | show | jobs
by mgraczyk 451 days ago
The simplest way is that all resources require an authenticated type for access, and getting that authenticated type requires an input (secret) only available on the server.

Facebook does something like this and it works pretty well