For REST service, is api.domain.com safer than domain.com/api?

I am considering which base URL to use for the REST web service. I have the opportunity to use one of the following formats:

I would like it to be easy to use with javascript client applications and protected from forged requests. Is there a best practice to follow here?

+3
source share
1 answer

If domain.com is a common domain, then each part should have its own subdomain, and no one should use the main domain, which is a prerequisite for the separation of all sessions.

domain.com , .

+2

Source: https://habr.com/ru/post/1772213/


All Articles