logoalt Hacker News

alabastervlog04/23/20251 replyview on HN

"Pulling a font for a domain"—wtf, isn't the client making the request? Why detect anything, just require a referrer on your allow-list, and deny if it's not there.


Replies

badmintonbaseba04/24/2025

An allow-list would probably suck for local development for users that do have a valid license.