4 ms·
I mean it's nowhere as bad, and for legacy stuff usually CORS/SOP helps. New implementations that use websocket as their root (mostly for web browser compatibi
by Hamcha 4y ago
I mean it's nowhere as bad, and for legacy stuff usually CORS/SOP helps.
New implementations that use websocket as their root (mostly for web browser compatibility) seem to take security more seriously out of the box, I use a couple apps in my day-to-day which expose APIs over Websocket and don't trust by default.
- Vtube Studio has a auth dialog that pops up on first connection you must accept before commands are executed
- obs-websocket by default requires a password to be used.
There's always outliers sadly, for example "beefweb" (Foobar plugin) has auth but it's not enabled by default.