Stop over-engineering shit, just do everything client-side like McDonald’s: https://bobdahacker.com/blog/mcdonalds-security-vulnerabilities
My friend who helped me research the OAuth vulnerabilities was let go for “security concerns from corporate”
Good old shooting the messenger.
I mean, they were an employee who was exploring security vulnerabilities with a non-employee who has a blog. I would have fired them too.
I work with several people who would think this is a good idea.
When they push it to prod, and our WAF goes
403on every request, then suddenly it’s my problem to “fix”.
(one of my favorite memes)
This is still over engineered. Just connect directly to the database from the client instead of having an API endpoint.
Too much overengineering there as well. Just copy the entire database into a google spreadsheet
Idk, let’s just make a public google sheets and share the link
What could possibly go wrong. Little Bobby Tables would be proud.
grapql in a nutshell
GraphQL:














