Closed
Description
Would you mind clarifying on this paragraph:
While that concept is appealing, it also has security implications. We always say that security by obscurity is not security, but providing attackers with full discoverability of your API is not necessarily wise.
What are you actually trying to express here? That hypermedia implies less security? That it implies security by obscurity? That discoverability implies less security?
Let me raise the counter question: if not though HATEOAS, how do you communicate security rules about which user is allowed to do what to clients and how is that approach more secure than the HATEOAS based approach?
Metadata
Metadata
Assignees
Labels
No labels