Every public endpoint already checked a nonce. Why add rate limiting?
· 4 min read
The question: an audit flagged "no rate limiting" on the framework's public AJAX endpoints. But every one of them verifies a nonce, sanitizes its input and validates it. Is a nonce not sufficient?
