• Kris@feddit.org
    link
    fedilink
    English
    arrow-up
    10
    ·
    15 hours ago

    I think now that Piefed has an API for apps, we will see some of them adding support soon. Overall I think the benefits of a Piefed migration outweight the disadvantages, but it remains to be seen if it is doable.

          • tfm@europe.pub
            link
            fedilink
            English
            arrow-up
            4
            ·
            10 hours ago

            It’s not just native Apps. Alternative web UIs like Thunder, Photon and Voyager need them too.

            • GreenKnight23@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              9 hours ago

              yes, but those frontends are typically tied closer to the backend than a public API.

              things like CSRF can help block abuse of the back end.

              • tfm@europe.pub
                link
                fedilink
                English
                arrow-up
                1
                ·
                9 hours ago

                Nope they all use the public API. Even the default Lemmy web client.

                • GreenKnight23@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  8 hours ago

                  well that’s poor planning and why bots are such a problem.

                  I know CSRF tokens aren’t a silver bullet, but doing nothing to stop them does nothing to stop them.

                  • tfm@europe.pub
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    ·
                    12 minutes ago

                    CSRF protection is a security feature not bot prevention. A bot would just need to get a token first.