mardi 24 février 2015

How to protect a public tracking API?


Let's say company X has websites A, B, and C. It would like to track how people are visiting them in ways that Google's Analytics and other services can't. So we company X provides a web API to track these metrics, and the API is to be called by the pages of A, B, and C through JavaScript.


How does one go about protecting this API from abuse?





Aucun commentaire:

Enregistrer un commentaire