We have an API key configured with a referrer restriction (https://*.ourdomain.com/* only), used in a public-facing web map built with MapLibre GL JS. Since the key is attached to tile requests client-side, it's unavoidably visible in the browser's network traffic to anyone who looks.
The referrer restriction doesn't seem to actually block anything. A plain curl request to a tile endpoint (e.g. .../VectorTileServer/tile/{z}/{y}/{x}.pbf?token=...) with no Referer header, or with a Referer set to a completely unrelated domain, still returns a full tile successfully. We even tried an obviously invalid/made-up token value and still got a valid tile back.
If that's accurate, then once the key is observed once (trivial, since it's public client-side), anyone could script a large volume of direct tile requests against it — bypassing the referrer restriction entirely — and dramatically increase our billed data load with no way for us to stop it at the key-configuration level.
Questions:
- Is the referrer restriction enforced server-side at all for tile requests, or is it only informational/logged rather than actually blocking non-matching referers?
- If it's only logged rather than enforced, can we at least filter/break down our usage dashboard by referer afterward, so we can identify and separate out traffic that didn't come from ourdomain.com?
- Is there an actual way to restrict usage by origin so requests from outside ourdomain.com are rejected (and not billed), rather than just allowed through?
Has anyone else run into this, or is there a key-configuration step we're missing that actually enforces this at the API layer?