|
|
|
|
|
by prng2021
54 days ago
|
|
Yes but my original reply was to someone that seemed to imply that this founder was dumb not to verify that Railway’s API key that should have been limited to managing custom domains, truly was limited to managing custom domains. I’ve never used Railway but my pushback is that no one in the real world exhaustively verifies a key is scoped properly against all 3rd party endpoints. We trust vendors to document how they’re scoped and to actually do that. |
|
It actually seems like they knew ahead of time and proceeded anyway, but are just using this critique as a way to shift blame.