Safety problems

In the registration form I have, I put an ajax call to check if the username is available.

However, I am concerned that this opens up a system for checking the bot for valid usernames.

How can I protect the service from external calls?

thank

+3
source share
2 answers

How can I protect the service from external calls?

Well ... ANY user trying to register will be an "external call"!

I do not see how verifying a username will pose a security risk. The bot could simply register as fsdjiojiejfiowell as be sure that no one had done this before.

, , .

+5

, , " ?" - , . , , , .

, , - , .

+1

Source: https://habr.com/ru/post/1782198/


All Articles