Suppose I have a web service used for increment/decrement uses' refos.
It may has these fields:
action: increment/decrement refos: 1000
The problem is, how can I know whether it's sent from firebug by a programmer or from my system?
I should respond to the action only if it's from my system.
The context is actually in a web game, where my system should increment the user's refos when some task is finished. But how do I deal with faking?
In reply to A question about web service security by Anonymous Monk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |