4 ms·
If you expose the OpenCensus service directly to the internet, then a malicious user could definitely send traces directly to it. We recommend in the blog post
by draffensperger 7y ago
If you expose the OpenCensus service directly to the internet, then a malicious user could definitely send traces directly to it.
We recommend in the blog post that you write an endpoint in your frontend web application that would proxy the writes of traces through it. That way you can add whatever rate limiting / authentication middleware you have for your overall application so that only logged in users can submit traces for your web app (or severely rate-limit those from unauthenticated users).
Basically, we are aware of this issue and our approach right now is to ask you to handle it in an application-specific way.