4 ms·
How does one implement a browser single-app JS client (Backbone, Angular etc) to access server API with HMAC authentication? The secret key will be exposed clea
by jemeshsu 14y ago
How does one implement a browser single-app JS client (Backbone, Angular etc) to access server API with HMAC authentication? The secret key will be exposed clearly in the JavaScript client.
- bvdbijl 14y agoYou give it an API key with limited access
- calpaterson 14y agoUnless you can use per-user keys (for example, if you control the server API) you basically can't do it. This is the same problem that DRM faces: you can't give the user the keys to the car and prevent them from driving it.
- jiggy2011 14y agoWow, that's a great analogy. I will use that next time I have to explain the flaws of client side security to somebody.