3 ms·
For the APIs, that'd be rate limiting and blacklist IPs. It doesn't completely stop spam, but would reduce them. Is there any other method should I be thinking
by docuru 6y ago
For the APIs, that'd be rate limiting and blacklist IPs. It doesn't completely stop spam, but would reduce them.
Is there any other method should I be thinking about?
- phillipseamore 6y agoI've used all kinds of things through the years; CAPTCHAs, expiring tokens, signed endpoint URLs. For local websites I've also simply blocked IP ranges from various countries (sometimes even down to all other states/countries). All your focus should be on doing validation at the endpoint, doing stuff on the client side (not related to validation at the endpoint) is a waste of time.
- docuru 6y agoHmm, true. Thanks for the useful insights