4 ms·
Caveat to the title: Except for local client-side data emissions. Filtering private data before it gets sent from your device in the first place is a good idea.
by Sephr 2y ago
Caveat to the title: Except for local client-side data emissions. Filtering private data before it gets sent from your device in the first place is a good idea.
- atoav 2y agoIf you can avoid making a request that to the knowledge of your client has to fail, don't make it. This has the benefit that it allows you to give clear and timely feedback to your client and potentially to your users. As for the problem outlined here: If you can reach any private, for-your-users-eyes-only endpoint without authentification you suck at what you do and you should probably change into a profession where you can deal less damage.
- manvillej 2y agoWith the caveat that you ALSO filter server side as well. You cannot rely on anything from the client.