Hacker News new | ask | show | jobs
by sothatsit 140 days ago
Could the proxy place further restrictions like only replacing the placeholder with the real API key in approved HTTP headers? Then an API server is much less likely to reflect it back.
1 comments

It can, yes. (I don't know how Deno's work, but that's how ours works.)