@akinkunmi Performance tradeoff honestly not Negligible" until you hit actual scale and your DB is crying from session lookups on every trivial GET request. The whole point of short-lived access tokens + stateful refresh tokens is getting the best of both worlds—massively reduced DB load
@echo_vick using uuid or maybe a timestamp with some random values that way they cannot call the script easily
- lastly disable running of an executable script in the uploads location maybe in your nginx configuration.
@echo_vick Uploads are actually a common way servers are hacked multiple options exists
- consider an actual bucket and save yourself the headaches. S3 or better still cloudflare r2 (quite cheap and awesome).
- u already mentioned validating the image however still change the file name
@Dominus_Kelvin And Yes I think the opinion not to use is valid like mad. whether or not I am the only one does not make it better. Just because a problem is global doesn't mean the local impact isn't worth discussing.
@PinkDraconian I have had this thougths for a bit, further emboldened because I did some map integrations a couple of hours ago, sadly the safest means is still "proxy call" approach. The new(old) oauth that is now enforced allows you to generate temporary access tokens that last 1hr also.
@Dominus_Kelvin I Agree with most if not everything you said. But I also feel the crashout is very valid, 2 truths can co-exist especially knowing their comeback is business and profit oriented and not like some favour or "I realized mistake".
@Dominus_Kelvin@rukky_nate@PayPal real economic consequences for legitimate builders. We can analyze the 'why' without acting like this comeback is a messianic favor—it’s a business expansion, not a rescue mission."
@Dominus_Kelvin@rukky_nate@PayPal "Emotions aren't facts, but they are valid responses to systemic exclusion. While we can acknowledge the historical fraud data that drove PayPal’s risk assessment, we shouldn't confuse corporate risk management with moral justice. Being 'caught in the crossfire' for a decade has