Hey there

I was wondering if the header HTTP_X_APPENGINE_INBOUND_APPID
could be faked by a client or if the Google Frontends authenticate this
header
somehow?

Is it secure to assume that if HTTP_X_APPENGINE_INBOUND_APPID is present,
the request is really from that app?

Cheers,
-Andrin

-- 
You received this message because you are subscribed to the Google Groups 
"Google App Engine" group.
To post to this group, send email to google-appengine@googlegroups.com.
To unsubscribe from this group, send email to 
google-appengine+unsubscr...@googlegroups.com.
For more options, visit this group at 
http://groups.google.com/group/google-appengine?hl=en.

Reply via email to