• tfm@europe.pub
        link
        fedilink
        English
        arrow-up
        2
        ·
        3 hours ago

        It’s not just native Apps. Alternative web UIs like Thunder, Photon and Voyager need them too.

        • GreenKnight23@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 hours ago

          yes, but those frontends are typically tied closer to the backend than a public API.

          things like CSRF can help block abuse of the back end.

          • tfm@europe.pub
            link
            fedilink
            English
            arrow-up
            1
            ·
            3 hours ago

            Nope they all use the public API. Even the default Lemmy web client.

            • GreenKnight23@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 hours ago

              well that’s poor planning and why bots are such a problem.

              I know CSRF tokens aren’t a silver bullet, but doing nothing to stop them does nothing to stop them.