Skip to content

Clarify on claims about security #9

Closed
@odrotbohm

Description

@odrotbohm

Would you mind clarifying on this paragraph:

While that concept is appealing, it also has security implications. We always say that security by obscurity is not security, but providing attackers with full discoverability of your API is not necessarily wise.

What are you actually trying to express here? That hypermedia implies less security? That it implies security by obscurity? That discoverability implies less security?

Let me raise the counter question: if not though HATEOAS, how do you communicate security rules about which user is allowed to do what to clients and how is that approach more secure than the HATEOAS based approach?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions