nw...@cornell.edu
unread,Jul 27, 2021, 1:09:09 PM7/27/21Sign in to reply to author
Sign in to forward
You do not have permission to delete messages in this group
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Firebase Google Group
Hello, I'm wondering how Firebase's App Check can prevent against fraud (via endpoint spam) on the web.
Specifically, on the web, with App Check (via reCaptchav3), is there protection from users who spam a particular endpoint. This abuse of course would not be possible through a CURL (from my understanding of how App Check functions), but would it be possible for the perpetrator in this case to instead write some Javascript (that would execute in the page) to spam a particular endpoint?
If so -- are there plans to protect against this or viable solutions to protect against this today?
Thank you!