• GreenKnight23@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    8 hours ago

    yes, but those frontends are typically tied closer to the backend than a public API.

    things like CSRF can help block abuse of the back end.

    • tfm@europe.pub
      link
      fedilink
      English
      arrow-up
      1
      ·
      8 hours ago

      Nope they all use the public API. Even the default Lemmy web client.

      • GreenKnight23@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        7 hours ago

        well that’s poor planning and why bots are such a problem.

        I know CSRF tokens aren’t a silver bullet, but doing nothing to stop them does nothing to stop them.