3 ms·
You can easily abuse non-serverless solutions as well... when signing the S3 request you could have internal logic and prevent this kind of behaviour, by just n
by tjholowaychuk 10y ago
You can easily abuse non-serverless solutions as well... when signing the S3 request you could have internal logic and prevent this kind of behaviour, by just not signing the request.
- mnutt 10y agoSure, though I think this is somewhat specific to serverless because in traditional applications, authentication usually covers all interactions with the user whereas with serverless you sometimes have to figure it out on a case-by-case basis. The article makes it sound like it accounts for it with CORS headers, which may mislead novices.