|
|
|
|
|
by prng2021
57 days ago
|
|
“why would you not do the same for APIs you integrate with?” Who does that? Jira and Salesforce have hundreds of endpoints each. AWS has hundreds of services, and each may have hundreds of endpoints. Who on your team is testing key scopes of every endpoint? Do you do it for each key you generate? After all, that external system could have a bug at any moment in managing scopes. Or they could introduce new endpoints that aren’t handled properly. So for existing keys, how frequently do you re-validate the scope against all the endpoints? |
|
if you want an llm to do any operations on your stuff, give it a role with access to only stuff you want it to be able to touch