Ask HN: How to stop people using my RSS reader web app as a proxy for evil sites
Due to CORS, the requests have to go through a server. The server also parses the rss feed and just returns a few bits of relevant information. The url, title, and date of the entries.
If I allow anyone to use my server to fetch any RSS feed they want.
What can I do to stop someone nefarious using my server as a proxy to build a list of links to evil/illegal things?
Other than building a database of trustworthy sites, which i'm not willing to do, I can't think of a solution.