Replies: 2 comments
-
Hello @hoanghiaquyen, thanks for your interest! In my opinion, if that's an issue then I'd recommend deploying it to a hosting infrastructure that supports spam prevention, such as a cloud provider implementing an API Gateway. Because, while it is possible to do something about spam within the application, I feel it should be an optional feature. But if we can find a nice design pattern to create a well-performing mechanism (and we keep it as an option that can be turned on/off), I don't see why we can't implement it then. |
Beta Was this translation helpful? Give feedback.
-
Thanks for reply. I think we can use rate limit for this or we can add IDNumber to claims thereafter check it in middleware (at least it doesn't enter the database to check but the security is not high) |
Beta Was this translation helpful? Give feedback.
-
Hi @bglamadrid. Thank you shared about this project. I have some question about flow "public/guest"
Thanks. Have a nice day
Beta Was this translation helpful? Give feedback.
All reactions