I'm developing a little website that makes use of TMDB data. It should let users search the TMDB database with a JavaScript function, but that would require me to send the API key to the browser, making it ultimately available to anyone, and I'm concerned about security. Is it a common practice for TMDB JavaScript clients to hold the API key? Are there any better practices for TMDB JavaSript development?
Não consegue encontrar um certo filme ou série? Inicie sessão e adicione-o.
Deseja classificar ou adicionar este item a uma lista?
Ainda não é um membro?
Resposta de Travis Bell
em 28 janeiro 2017 às 11:04 AM
Yes, there's not going to be much you can do. We don't worry too much about this. Since we offer our service for free, there really isn't much of a reason to steal someone else's key. Having said that of course, if you feel like your key was stolen and has activity on it that isn't yours, we can always shut it down and issue another.
Resposta de lucrus
em 29 janeiro 2017 às 5:02 AM
In this case, from your point of view, you have a rate limit in place, so the worst you can face is a key revocation and issue of another one. From my point of view, it would be a DoS. I think I'll move the TMDB code on the server and provide my clients with my own webservices then. Thanks for the help.